Legal
Security
Last updated October 8, 2026 · Version 2026-10-08
Our posture in one paragraph
GoFindStuff runs entirely over HTTPS, hashes passwords with bcrypt (cost factor 12), issues short-lived JWT access tokens alongside refresh tokens, locks accounts after repeated failed sign-in attempts, and stores all media in AWS S3 with provider-managed encryption at rest. We don't sell or share your data, and the only third parties that ever see it are the sub-processors named in our Privacy Policy.
What we do
- Transport. HTTPS everywhere with HSTS via AWS Amplify-managed certificates. HTTP redirects to HTTPS at the edge.
- Authentication. Passwords are hashed with bcrypt at cost factor 12. We issue short-lived JWT access tokens (15 minutes) and longer-lived refresh tokens (7 days) that can be revoked. After five failed sign-in attempts the account is temporarily locked.
- Authorization. Every read and write request is bound to your authenticated user — we never trust a
userIdfrom the query string. - Encryption at rest. Media is stored in AWS S3 with provider-managed server-side encryption. Database content is encrypted at rest by MongoDB Atlas.
- Input validation. Every API endpoint validates inputs with Zod schemas before they reach the data layer. Uploads are checked for MIME type and size limits on the server, not just in the browser.
- Rate limiting. Authentication endpoints (sign-in, sign-up, password reset) are rate-limited per IP and per account, with exponential back-off on repeated failures.
- Dependencies. We track
npm auditon every release and patch high and critical advisories before deploying. - Logging. Server-side request logs are retained for up to 30 days for security and rate-limiting purposes. Sensitive values (passwords, tokens, API keys) are never written to logs.
What we don't do
- We don't sell your data or share it with advertisers.
- We don't train AI models on personally identifiable user content. AI inference happens at request time and the content is not retained by our inference providers for training (see Privacy Policy for the sub-processor list).
- We don't claim “end-to-end encryption.” Your content is encrypted in transit and at rest, but we hold the keys — that is the standard, but it isn't E2E in the technical sense.
- We don't run third-party analytics, advertising pixels, session-replay tools, or social trackers on the marketing site at gofindstuff.com.
Reporting a security issue
If you believe you've found a vulnerability in GoFindStuff, please report it privately by emailing legal@gofindstuff.com with as much detail as you can — a proof-of-concept request, steps to reproduce, your assessment of impact, and whether you want to be credited if we publish a fix.
We try to acknowledge reports within two business days and to deliver a substantive update within 30 days. We do not currently operate a paid bug-bounty program, but we are happy to publicly credit researchers who report responsibly.
Please do notpublish the issue before we've had a chance to address it, attempt to access another user's data, run automated scans that disrupt the service, or test against accounts that aren't yours.
Scope
Reports we're actively looking for:
- Authentication and session-handling flaws.
- Authorization bypass (IDOR / horizontal or vertical privilege escalation).
- Server-side injection (SQL/NoSQL/command/SSRF).
- Cross-site scripting that survives React's default escaping.
- Account-takeover paths through password reset, refresh-token handling, or email enumeration.
- Data exposure via the public marketplace, listings, or messaging surfaces.
Out of scope:
- Findings that require physical access to a user's device.
- Self-XSS or social-engineering that requires the user to paste code into their own console.
- Missing security headers without a demonstrable impact path.
- Volumetric DoS without a novel amplification.
- Issues in third-party services that are reportable to those services directly.
Where to find more
- How we handle your data: Privacy Policy
- What we don't allow on the platform: Acceptable Use Policy
- Copyright takedown procedure: DMCA Policy
- General terms of use: Terms of Service
Contact
GoFindStuff LLC
1403 W Braymore Cir
Naperville, IL 60564
United States
Security: legal@gofindstuff.com
Privacy: privacy@gofindstuff.com