NogenTechNogenTech
Security & privacy

How we protect account and report data

A product-level overview of the protections built into the application today — account-scoped access, private reports, and server-side secrets. Security practices continue to mature before production launch.

No card required for the 3 free analyses after verified signup.

How it's handled

Your content, handled deliberately

A signed-in account passes an access check that scopes data to that account, producing a private report the public site never loads.

The overview

Where account and report data are guarded

Six areas of the application, and what's actually implemented in each — not a marketing checklist.

S1

Authentication and sessions

Accounts use email-based authentication with email verification before free analyses unlock. Sessions are stored server-side for the authenticated application.

S2

Protected application routes

Projects, analyses, and reports require a signed-in account. Access checks keep data scoped to the owning account.

S3

Private reports

Live reports are private. The public marketing site never loads private account, project, credit, or report data. The public sample report is fictional demonstration content only.

S4

Provider processing

Analysis may use AI and search-research providers configured on the application servers. Provider credentials stay server-side. Operational logging is designed to avoid recording full article bodies, and report excerpts used in findings are capped.

S5

Credits and report storage

Credit reservation and report storage run as transactional application operations, so a useful report and credit spend stay aligned.

S6

Public marketing site separation

The marketing site builds and runs without database credentials, authentication secrets, or provider credentials.

In plain terms

What we do — and what we don't

The same facts above, stated plainly, plus what's deliberately out of scope.

What we do

  • Require a signed-in, verified account before projects, analyses, or reports are accessible.
  • Scope every access check to the owning account.
  • Keep report data private — the public site never loads it.
  • Keep provider and application credentials server-side, off the public marketing build.
  • Reserve a credit only when submitting, and spend it only once a useful report is stored.
  • Cap report excerpts and avoid logging full article bodies during provider processing.

What we don't

  • Crawl your site. Analysis runs only on the content you paste or fetch for that submission.
  • Load private account, project, credit, or report data on the public marketing site.
  • Charge a credit for a run that fails — reservations are released, not spent.
  • Ship database, authentication, or provider credentials in the public marketing build.
  • Present formal compliance certifications or absolute security guarantees.

This overview does not present formal compliance certifications or absolute security guarantees. Security practices continue to mature before production launch.

Privacy notice (draft) · Report a security concern · [email protected]

See it on your own draft, free.

Create an account and run your first analysis. Three analyses, no card required — your data stays scoped to your account from the first run.

Start with 3 free analysesNo card required · Account-scoped access