Trust

Security at CreatorX AI

This page is maintained by the CreatorX AI team to answer common security and privacy questions about the product. It describes controls currently enabled in the app — not a certification or audit.

Last updated: July 22, 2026

1. Encryption

All traffic between your browser and CreatorX AI is served over HTTPS with TLS. Data at rest in our managed database and object storage is encrypted by the underlying cloud provider. Passwords are never stored in plain text — they are hashed on our authentication provider.

2. Authentication & account access

Sign-in is handled by our managed auth provider. We support email/password with mandatory email verification, plus Google Sign-In. Password reset uses signed, time-limited links.

Sessions use secure, HTTP-only tokens. You can sign out of your account at any time from the Profile page.

3. Row-level data isolation

Every user-owned table in our database enforces row-level security, so your projects, generations, chat threads, payments and settings are only readable by your account. Server functions that touch privileged data verify the caller's identity before running.

4. Payments

Payments are processed by Razorpay. We never see or store card, UPI or netbanking credentials. Our server verifies every Razorpay signature and webhook before granting a plan or credits, and stores only the order ID, payment ID, amount and status.

5. Content privacy

Your prompts, uploads and generated outputs are private to your account. We do not use your content to train third-party models where the provider offers a no-training option, and we do not sell your data.

6. Application security controls

Standard hardening is applied at the edge and in the app:

  • HTTPS enforced on all custom domains.
  • Security headers: X-Content-Type-Options, X-Frame-Options: SAMEORIGIN, Referrer-Policy, Permissions-Policy, HSTS.
  • Server-side input validation with Zod on every server function.
  • Webhook endpoints verify HMAC signatures before processing.
  • Least-privilege service role — never exposed to the browser.

7. Responsible disclosure

If you believe you have found a security vulnerability, please email security@creatorxsuite.com with a description, reproduction steps and any proof-of-concept. We ask that you:

  • Give us a reasonable window to investigate and fix before public disclosure.
  • Do not access, modify or delete data that isn't yours.
  • Do not run denial-of-service or spam tests against production.

We aim to acknowledge reports within 3 business days.

8. Incident response

If we confirm a security incident that affects your data, we will notify affected users by email with what happened, what data was involved and what we're doing about it, within timelines required by applicable law.

9. Shared responsibility

Security is a shared responsibility. Please use a strong, unique password, keep your email account secure, and sign out from shared devices. Report any suspicious activity on your account to support@creatorxsuite.com.

10. Contact

Security issues: security@creatorxsuite.com. Privacy questions: privacy@creatorxsuite.com.

Questions? Contact support@creatorxsuite.com.