Security & Privacy
A practical overview of the safeguards currently used by Asterforth, along with important limitations that users should understand.
Account security
Asterforth requires strong passwords and uses password hashing, rate limiting, temporary login lockouts, and secure session-cookie settings in production. Email delivery for verification and password-reset messages is not yet configured, and automated bot protection is not currently implemented.
Encryption in transit
The deployed application is configured to use HTTPS at the hosting edge, along with security headers and HTTP Strict Transport Security in production. No online service can guarantee complete security.
Access to information
The platform is designed to limit workspace information according to authenticated accounts, case membership, and user roles. Authorized service providers and personnel may process information where needed to operate, secure, support, or comply with legal obligations. Do not enter information that is not necessary for the service.
How information is stored
Account, case, financial, task, consent, communication, and document-record information may be stored in the platform database. The current implementation stores document records and metadata; users should not assume that every document-storage feature is available. Do not submit Social Security numbers, full bank or card numbers, passwords, medical records, or other unnecessary highly sensitive information.
Sale and advertising
The current application code does not implement targeted advertising or a mechanism for selling user information. Operational and contractual practices remain governed by the Privacy Policy and should be reviewed there.
AI data handling
When an AI-assisted feature is used, relevant prompts, conversation content, and context may be sent to OpenAI for processing, and conversation messages may be retained by Asterforth. OpenAI retention, transfer, and model-training treatment depends on the applicable provider configuration and terms and has not been independently verified here. Avoid entering information you do not want processed by an AI provider.
Deletion requests
Account Settings allows a user to request account deletion. A request is recorded, the active session is ended, and the request is manually reviewed. This is not an immediate automated erasure process, and some records may be retained where legally or operationally necessary.
Backups
The application does not promise a fixed backup schedule, retention period, restoration timetable, or backup-deletion deadline. These operational details should be confirmed before making additional public claims.
Privacy and security questions
Contact privacy@adriaticmediation.com. Also review the Privacy Policy, Terms of Use, and Disclaimer.