Security Policy & Architecture
Last updated: October 7, 2026
TeenFounders is dedicated to providing an empowering, safe, and transparent ecosystem for builders. Please review our policies carefully.
Overview & Commitment
At TeenFounders (operated by Trooth Allied Private Limited), the safety and security of young founders and creators is paramount. We build defense-in-depth security mechanisms into every layer of our stack to protect personal records, intellectual property, and real-time communications.
Our security model is built on strict data segregation, encrypted communications, automated content and media scanning, and proactive vulnerability monitoring.
Data Encryption & Storage
We implement high-grade industry standards for data transit and persistence:
- Encryption in Transit: All HTTP and WebSocket traffic is protected using TLS 1.3 with Strict Transport Security (HSTS) forced across all domains.
- Encryption at Rest: Database assets, user state records, and media files are encrypted at rest using AES-256 standard encryption.
- Row Level Security (RLS): Granular Postgres RLS policies ensure that users can only query and mutate data they own or have explicit authorization to view.
- Ephemeral Verification Media: Sensitive identity verification assets are stored in isolated encrypted storage buckets accessible strictly via short-lived signed URLs.
Authentication & Access Control
TeenFounders uses hardened OAuth 2.0 flows, PKCE session verifications, and cryptographic nonces for Content Security Policy compliance.
- Secure HttpOnly, SameSite cookie strategies preventing cross-site scripting session exfiltration.
- Turnstile bot and DDoS challenges protecting login, onboarding, and messaging endpoints.
- Role-based access control isolating administrative functionalities from standard platform users.
Responsible Vulnerability Disclosure
We welcome contributions from security researchers and white-hat hackers who help keep our community safe. If you discover a vulnerability or security flaw, please report it responsibly.
How to report a vulnerability:
Email full details and reproduction steps to [email protected]. We review submissions within 24-48 business hours and do not pursue legal action against researchers acting in good faith.
TeenFounders is a product of Trooth Allied Private Limited.
© 2026 TeenFounders • All rights reserved