What is in place
All traffic is served over HTTPS with HSTS. Every response carries a Content-Security-Policy, framing is denied, MIME sniffing is disabled, and the referrer and permissions policies limit what leaks to other sites. Secrets are held server-side and never exposed to the browser.
What is not yet in place
Authentication, two-factor, per-user authorisation, encrypted file storage, payment tokenisation, audit logging and tested backups are built into the plan but not yet live. The Data & Security page lists them explicitly rather than implying they already exist.
What we do not claim
Researchor holds no security certification: no SOC 2, no ISO 27001, no third-party penetration test. We do not claim end-to-end encryption, because we do not have it.
Any platform displaying those badges without the underlying audit is lying to you. We would rather tell you where we actually are.
Your rights
Access, correction, deletion, restriction, portability and consent withdrawal, wherever you live. Most are available in Settings; the rest by writing to support. See the Privacy Policy.
Reporting a vulnerability
Email support@researchor.org.ng with enough detail to reproduce it. We will not pursue a researcher who reports in good faith, does not access other users' data, and does not degrade the service.