Security & Trust

Security Policy & Architecture

Last updated: October 7, 2026

TeenFounders is dedicated to providing an empowering, safe, and transparent ecosystem for builders. Please review our policies carefully.

Overview & Commitment

At TeenFounders (operated by Trooth Allied Private Limited), the safety and security of young founders and creators is paramount. We build defense-in-depth security mechanisms into every layer of our stack to protect personal records, intellectual property, and real-time communications.

Our security model is built on strict data segregation, encrypted communications, automated content and media scanning, and proactive vulnerability monitoring.

Data Encryption & Storage

We implement high-grade industry standards for data transit and persistence:

  • Encryption in Transit: All HTTP and WebSocket traffic is protected using TLS 1.3 with Strict Transport Security (HSTS) forced across all domains.
  • Encryption at Rest: Database assets, user state records, and media files are encrypted at rest using AES-256 standard encryption.
  • Row Level Security (RLS): Granular Postgres RLS policies ensure that users can only query and mutate data they own or have explicit authorization to view.
  • Ephemeral Verification Media: Sensitive identity verification assets are stored in isolated encrypted storage buckets accessible strictly via short-lived signed URLs.

Authentication & Access Control

TeenFounders uses hardened OAuth 2.0 flows, PKCE session verifications, and cryptographic nonces for Content Security Policy compliance.

  • Secure HttpOnly, SameSite cookie strategies preventing cross-site scripting session exfiltration.
  • Turnstile bot and DDoS challenges protecting login, onboarding, and messaging endpoints.
  • Role-based access control isolating administrative functionalities from standard platform users.

Responsible Vulnerability Disclosure

We welcome contributions from security researchers and white-hat hackers who help keep our community safe. If you discover a vulnerability or security flaw, please report it responsibly.

How to report a vulnerability:

Email full details and reproduction steps to [email protected]. We review submissions within 24-48 business hours and do not pursue legal action against researchers acting in good faith.

TeenFounders is a product of Trooth Allied Private Limited.

© 2026 TeenFounders • All rights reserved