SEMSTREND

Security & Trust

DRAFT — This page will update automatically once the lawyer-approved final text is uploaded from the admin panel.

At SemsTrend, trust is not a marketing slogan; it is an architectural decision. These are the safeguards we apply: DATA TRANSMISSION • All traffic is encrypted end-to-end with TLS (HTTPS); unencrypted connections are not accepted. • Session cookies are marked httpOnly + secure + sameSite; browser scripts cannot access them. IDENTITY AND ACCESS • Access is available only to accounts on the authorized user list (allowlist). • Access codes are stored as irreversible scrypt hashes — plain-text codes are never stored anywhere. • Sessions are signed with HMAC-SHA256 and valid for 7 days. All sessions can be revoked instantly in bulk with a single central key (epoch). • Only the founder can authorize a new user; every access change is recorded. DATA STORAGE • Data is stored on managed PostgreSQL infrastructure hosted in the European Union (Frankfurt). • Database connections use encrypted channels; access credentials are kept in environment variables, not embedded in code. • Every radar run is recorded in a traceable way with its source, quality, and decision chain (provenance). PAYMENTS • Payments are accepted only through the Apple App Store / Google Play. Your card details NEVER reach our servers. • Subscription validation is performed server-side using the store receipt. DATA POLICY • Your data is not sold to third parties. • KVKK and GDPR principles are observed; deletion requests are handled through the address on the contact page. For security questions or reports: support@aresta.online

Last updated: 8/6/2026 · SemsTrend · innovation drives technology forward