Draft for legal review
This is a plain-English draft for the Human Made pilot. A lawyer has not reviewed it yet, and it may change before the final version.
Security
How Human Made protects designers' and brands' data, and how to report a security problem.
Version 2026-10-02. Last updated 2 October 2026. Human Made, operated by Kyle Yeoman.
How we protect Human Made
- Every page and file is served over HTTPS, with strict security headers.
- Each brand's data is kept apart in the database itself, not only by the app. Asking for another brand's records returns not found.
- Passwords are hashed with argon2id and checked against known breached passwords. Two-factor sign-in is required for brand roles that handle data and for the operator, and open to every designer.
- Sessions are checked on every request, time out when idle, and can be signed out from Account, then Sessions.
- Sign-in links, invites and recovery codes are single use and stored only as hashes.
- Uploads are checked by their contents, not their names. Images are re-saved, which removes hidden data such as location.
- Important actions go to an audit log that the app cannot edit. Everyone can see their own security events in Account, then Security.
- Support access to a brand's workspace by Human Made, operated by Kyle Yeoman is read only, needs a written reason, lasts at most 60 minutes and is recorded in the brand's audit log.
The services we use to run Human Made are listed on the Subprocessors page.
Report a security problem
Email kylepyeoman@gmail.com with what you found, the steps to reproduce it, and the pages or accounts involved. Please do not put details in public places until we have fixed it.
We will confirm we got your report within 3 business days, keep you updated, and tell you when it is fixed. Our contact details are also in security.txt.
Rules for security research
- Test only with accounts you own or have permission to use.
- If you reach data that is not yours, stop, do not keep or share it, and tell us.
- Do not change or delete data, slow the service down, send spam, or try to trick people.
- Do not test the services we use, such as Vercel, Neon, Google or Cloudflare. Report problems in them to those companies.
- Give us a reasonable time to fix a problem before you talk about it publicly.
If you follow these rules in good faith, we will not take legal action against you for your research, and we will thank you. Human Made does not pay bug bounties during the pilot.
If something goes wrong
We can turn off sign-ups or uploads, put Human Made in read-only mode, and sign everyone out while we deal with a problem. If a breach affects a brand's data, we tell that brand's Owners within 72 hours of becoming aware of it, and we tell affected people when the law requires it.
Contact
Security reports and questions: kylepyeoman@gmail.com.