Effective date: September 25, 2026
Rocketing, LLC takes the security of MagicTrees.ai and your data seriously. This statement describes our approach; it is not a warranty and does not claim certifications we do not hold.
Our Approach
Defense-in-depth practices, including a secure development lifecycle, code review, and least-privilege access.
Technical Controls
- Encryption in transit; encryption at rest where supported by our infrastructure providers.
- Centralized secrets management; credentials are never stored in code.
- Network segmentation, monitoring, and alerting.
- Authentication provided by Clerk; payments processed by Stripe, which is PCI DSS certified — we do not store full card numbers.
Vulnerability Management
Regular patching and dependency updates, and periodic third-party testing.
Incident Response
We maintain an incident response plan with roles, timelines, and notification criteria. We will notify affected users where required by law.
Responsible Disclosure
Report vulnerabilities to security@magictrees.ai. Please do not test against production data or other users' accounts without authorization. We will acknowledge good-faith reports and work with you to resolve confirmed issues.
Vendors and AI Providers
Cloud and AI providers (OpenAI, Anthropic and Google) are assessed for security posture and contractual protections before use.