Legal and safety
Security Policy
Version 2026-08-10
Security Policy
Effective date: 2026-08-10
Policy version: 2026-08-10
Togetha uses reasonable safeguards for the current stage of the product and improves them as the platform matures.
Current safeguards
The platform uses password hashing, signed HTTP-only session cookies, CSRF protection for browser form posts, admin-only routes, organization permission checks, private calendar tokens that can be rotated, audit logs, health checks, Docker deployment, staging validation, and database backup practices.
Vulnerability reports
Please report suspected vulnerabilities to support@togetha.live with a clear description, affected URL, steps to reproduce, and any relevant screenshots or logs.
Testing boundaries
Do not access, modify, delete, or exfiltrate other users' data. Do not run destructive tests, denial-of-service attacks, spam, phishing, social engineering, or automated scraping against Togetha.
Security incidents
Togetha will investigate credible security reports, take reasonable containment steps, preserve relevant records, and handle notifications according to applicable law.
No guarantee
No online service can guarantee complete security. Users should use strong passwords and report suspicious activity.