Security

Last updated: 2026-10-09

Keeping your recordings, scripts and connected accounts safe is part of the service. This page describes how KolReel is protected and how to report a security issue to us.

How the service is protected

  • Hosting: KolReel runs on dedicated servers at Hetzner in the European Union. The servers are reachable only over HTTPS; SSH administration uses keys only, is rate limited and is monitored by fail2ban.
  • Encryption: all traffic is encrypted with TLS (HSTS is enabled). Access tokens for connected services (Google, Meta, TikTok, Microsoft, Dropbox, Canva) and any AI provider keys you save are stored encrypted at rest and are never sent to the browser.
  • Sign-in: no passwords are stored. You sign in with a one-time code sent to your email or phone, or through Google, Facebook, Microsoft or TikTok sign-in. Sessions use secure, same-site cookies.
  • Payments: card details are entered on our payment provider's page and never touch our servers. We keep only a payment token, the card brand and the last four digits.
  • Connected services: we request only the permissions each integration needs, validate every OAuth redirect and state parameter, and you can disconnect a service at any time, which deletes its tokens immediately.
  • Backups: encrypted backups are taken nightly and copied to a separate object storage location in the EU. They are kept for 30 days.
  • Updates and checks: security updates are applied regularly; an automated check runs every six hours and verifies the firewall, SSH configuration, pending security updates and the vulnerability status of the application's dependencies (Composer advisories). The code base is checked with static analysis (Larastan) before every release.

Reporting a vulnerability

If you believe you have found a security issue in KolReel, please email security@kolreel.com with a description, the steps to reproduce it and, if possible, the affected URL. We acknowledge reports within three working days and keep you informed while we fix the issue. Please give us a reasonable time to fix it before any public disclosure, do not access data that is not yours, and do not run tests that could degrade the service for others (for example load testing or automated scanners against production). We do not run a paid bug bounty programme at this time, but we are happy to credit reporters who ask for it.

Machine-readable details are published at /.well-known/security.txt.

v. 2026-10-10