Skip to content
Built by friends, for friends.

Security

Last updated: January 2025

At Waypoints, security is a core principle, not an afterthought. This page explains the measures we take to protect your data and how you can report security vulnerabilities.

1. Encryption

All data transmitted between the Waypoints client and our servers is encrypted using TLS (Transport Layer Security). Direct messages are end-to-end encrypted, meaning only you and the intended recipient can read them. Voice and video data is encrypted in transit using DTLS-SRTP.

2. Data Storage and Protection

Your password is stored as a bcrypt hash, never in plaintext. Sensitive data at rest is encrypted using industry-standard algorithms. Access to production systems is restricted and logged. We do not store voice or video data unless a participant explicitly records a session.

3. Transparency

We are committed to transparency about how Waypoints works. We publish clear documentation about our security practices, encourage responsible disclosure of vulnerabilities, and welcome feedback from our community. We believe transparency builds trust.

4. Authentication and Access Control

We use token-based authentication with short-lived session tokens. Two-factor authentication (2FA) support is on our roadmap. Server administrators can configure role-based access controls to manage permissions within their communities.

5. Incident Response

In the event of a security incident, we will: (1) assess and contain the incident, (2) notify affected users within 72 hours as required by LGPD Article 48, (3) report to ANPD where required, and (4) provide transparent post-incident communication.

6. Responsible Disclosure

If you discover a security vulnerability, we encourage responsible disclosure. Please report it to suporte@waypoints.com.br with a detailed description and steps to reproduce. We commit to:

  • Acknowledging receipt within 48 hours.
  • Providing an initial assessment within 5 business days.
  • Not taking legal action against good-faith security researchers.
  • Crediting reporters in our security advisories (with permission).

Please do not publicly disclose vulnerabilities until we have had time to address them.

7. Security Tips for Users

You can help keep your account secure by:

  • Using a strong, unique password for your Waypoints account.
  • Enabling two-factor authentication when it becomes available.
  • Never sharing your account credentials with anyone.
  • Being cautious of links and files shared by unknown users.
  • Reporting suspicious activity to your server moderators or to us at suporte@waypoints.com.br.

8. Contact

For security questions or vulnerability reports, contact us at suporte@waypoints.com.br. For urgent security matters, please use PGP encryption (key available on our security page).