AskCc
Sign in

Security Practices

Last Updated 2026-08-13

This page describes security practices currently used by AskCc. It does not promise identical architecture across every provider, partition, or feature and does not create an additional service-level agreement.

1. Infrastructure and risk management

AskCc uses configured cloud, database, and private object-storage services and applies logical account boundaries, transport protections, and available backup or recovery measures appropriate to the partition and feature.

We assess vulnerabilities and risks using severity, exploitability, user impact, and current operational capacity. Unless separately agreed in writing, this page does not promise a fixed testing frequency or remediation SLA.

2. Identity and application controls

Account and administrative access uses authentication, session, and role controls appropriate to the current systems; specific capabilities may vary by partition and feature.

Users must protect devices, verification channels, and account sessions. If suspicious activity or credential exposure is detected, AskCc may invalidate sessions, restrict access, or require reauthentication.

3. Monitoring and incident response

AskCc retains operational, billing, and security event records reasonably needed to investigate faults, abuse, unauthorized access, and payment disputes. Monitoring depth and retention may differ across systems.

We investigate confirmed incidents and take reasonable containment and remediation measures, notifying affected users or authorities when required by applicable law or contract. Timing depends on fact verification, incident control, and legal requirements.

4. Reporting security issues

AskCc provides security or compliance materials only when they exist, can be shared safely, and the applicable commercial arrangement permits it. Provider certifications do not automatically mean AskCc as a whole holds the same certification.

Report suspected vulnerabilities to security@pyznai.com with the affected feature, reproduction steps, and evidence you can safely share. Do not access other users' data, disrupt the service, use social engineering, or condition a report on payment; reporting does not automatically create a bounty or compensation right.

Security FAQ

Is AskCc data encrypted?

AskCc uses transport and storage protections appropriate to the product partition, configured services, and feature. Specific controls may differ and do not constitute a uniform certification or service-level commitment.

Who can access production data?

AskCc limits production access to authorized operational needs such as support, reliability, abuse prevention, or legal compliance. Access should be role-based, logged where appropriate, and kept narrower than general product analytics.

What happens if there is a security incident?

AskCc investigates reported security events, works to contain and remediate confirmed issues, and notifies affected users or authorities when required by law, contract, or product policy.

How do I report a vulnerability or security concern?

Send details to support@pyznai.com, including affected pages, accounts, reproduction steps, and any evidence you can safely share. Avoid accessing other users' data or disrupting the service while reporting an issue.