Security & Privacy at InkWell
Your trust is our foundation. We implement enterprise-grade protections to safeguard writer data, reader privacy, and platform integrity.
End-to-End Encryption
All data is encrypted in transit using TLS 1.3 and at rest with AES-256. Your drafts, messages, and personal information never leave our secure infrastructure unencrypted.
Zero-Trust Architecture
We enforce strict role-based access controls, mandatory MFA for staff, and continuous session validation. Least-privilege principles apply across all internal systems.
Content Integrity
Immutable publishing logs, anti-plagiarism safeguards, and automated copyright detection protect original work. Writers retain full ownership and control of their content.
Privacy-First Design
No tracking pixels, no third-party analytics, no data selling. We practice data minimization and provide transparent cookie controls in full compliance with global regulations.
Incident Response
24/7 threat monitoring, automated anomaly detection, and a documented response playbook. We commit to <24 hour disclosure of confirmed security incidents.
Third-Party Audits
Annual penetration testing, quarterly code reviews, and continuous dependency scanning. Full audit reports are available upon request for enterprise clients.
Compliance & Certifications
Report a Vulnerability
We welcome responsible disclosure. Our security team actively monitors reports and provides timely acknowledgments, remediation updates, and recognition.
Email Contact
PGP Key
Fingerprint: 8A92 3C1D E4F6 7B02 9E15
Response SLA
Acknowledgment within 24 hours. Critical severity prioritized.