Last Updated: August 17, 2025 | Version 3.0.0
At TextIt Corporation, we prioritize the security of our software and the protection of our users' data. This document outlines our security policies, procedures, and best practices for maintaining a secure environment.
- Supported Versions
- Reporting Security Issues
- Security Response Process
- Security Measures
- Secure Development
- Compliance & Certifications
- Security Best Practices
- Incident Response
- Contact Information
| Version | Status | End of Support |
|---|---|---|
| 3.0.x | β Active | December 31, 2026 |
| 2.0.x | December 31, 2025 | |
| < 2.0 | β EOL | Not supported |
Note: Critical security patches may be backported to maintenance versions for a limited time.
We take all security vulnerabilities seriously. If you've discovered a security issue in TextIt, we appreciate your help in disclosing it to us in a responsible manner.
- Do not publicly disclose the vulnerability
- Submit your report via one of these methods:
- GitHub Security Advisories: Report a Vulnerability
- Email: security@TextItCorporation.com (include "[TextIt Security]" in subject)
- PGP Encrypted: Download our PGP Key
For efficient processing, please include:
-
TextIt version affected
-
Steps to reproduce the issue
-
Impact of the vulnerability
-
Any proof-of-concept code (if available)
-
Your contact information
-
Detailed description of the vulnerability
-
Step-by-step reproduction instructions
-
Impact assessment
-
Any proof-of-concept code (if available)
-
Your contact information
-
Preferred method for acknowledgment
- Response Time: Initial response within 24 hours
- Assessment: Triage within 3 business days
- Resolution: Fix timeline based on severity
- Recognition: Public acknowledgment (unless requested otherwise)
- Acknowledgement: You'll receive a confirmation of your report
- Validation: Our security team verifies the vulnerability
- Prioritization: Based on CVSS score and impact
- Remediation: Development of a fix
- Testing: Security and regression testing
- Release: Deployment of the security update
- Disclosure: Public announcement (coordinated with reporter)
-
Multi-Factor Authentication (MFA)
- Time-based One-Time Passwords (TOTP)
- Biometric authentication
- Hardware security keys (FIDO2/U2F)
- SMS/Email OTP fallback
-
Password Security
- Argon2id with appropriate work factors
- Minimum 12-character requirement
- Password strength meter
- Breached password detection
- Passwordless authentication options
-
Encryption
- AES-256-GCM for data at rest
- TLS 1.3 for data in transit
- Field-level encryption for sensitive data
- Secure key management with AWS KMS
-
Database Security
- Row-level security
- Dynamic data masking
- Automated backups with encryption
- Regular security patching
-
Input Validation
- Strict type checking
- Input sanitization
- Content Security Policy (CSP)
- Anti-CSRF tokens
-
API Security
- OAuth 2.1 with PKCE
- Rate limiting and throttling
- Request validation
- Comprehensive logging
- Secure coding standards (OWASP ASVS)
- Automated security testing in CI/CD
- Dependency scanning (Snyk, Dependabot)
- Regular security training for developers
- Threat modeling for new features
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Penetration testing (quarterly)
- Bug bounty program
- GDPR compliant
- CCPA compliant
- SOC 2 Type II (in progress)
- ISO 27001 (target Q4 2025)
- Regular third-party security audits
- Monthly security patches
- Dependency updates (automated)
- Infrastructure as Code (IaC) scanning
- Container vulnerability scanning
- SIEM integration
- Real-time alerting
- Anomaly detection
- 90-day log retention
Our incident response team is available 24/7 to address security incidents. In case of a security breach:
- Containment: Isolate affected systems
- Eradication: Remove the threat
- Recovery: Restore services
- Post-Mortem: Document and learn
For security-related inquiries:
- Security Team: security@TextItCorporation.com
- Emergency: +91 99999-88888 (24/7)
- PGP Key: Download
- Security Mailing List: security-announce@TextItCorporation.com
We follow responsible disclosure guidelines and will work with security researchers to validate and address reported vulnerabilities. We ask that you:
- Allow us a reasonable time to address the issue
- Not exploit the vulnerability or access/modify user data
- Keep the issue confidential until we've had time to address it
This Security Policy is licensed under the Creative Commons Attribution 4.0 International License.
Β© 2025 TextIt Corporation. All rights reserved.
123 Tech Park, Near Sola Road, S.G. Highway, Ahmedabad, Gujarat 380061, India
Security updates will be announced through:
- GitHub security advisories
- Release notes
- The official TextIt communication channels
We recommend that users of TextIt follow these security best practices:
- Use strong, unique passwords
- Keep your client software updated to the latest version
- Be cautious about the information you share through the platform
- Report any suspicious activity immediately
Thank you for helping keep TextIt and our users safe!