Security at My Treat
How we protect the people, businesses, and data on our platform.
The short version. My Treat is built and run by a cybersecurity professional. Security is a design constraint from the first commit -- not a feature added later.
How we protect you
- Everything is encrypted -- in transit (TLS) and at rest (AES-256), on every data store.
- We never sell your data -- and we run no ad-tracking pixels on our sign-in or billing pages.
- Strong account protection -- company accounts are anchored to hardware security keys, and business accounts can add multi-factor authentication.
- Email you can trust -- our domain enforces modern anti-spoofing standards, so mail claiming to be from My Treat that isn't gets rejected.
- Minimal vendors, managed secrets -- a deliberately small set of third-party services, with production credentials kept out of the codebase in managed secret storage.
- Your data, your call -- account and data deletion through our published deletion process.
Report a vulnerability
We welcome reports from security researchers. Our security.txt file follows RFC 9116.
Report a vulnerability: security@mytreat.club
We respond promptly and take every report seriously. We do not pursue legal action against researchers acting in good faith.
With your permission, we credit researchers here after a report has been validated and fixed.
Contact