Security
A factual map of safeguards that are present, controls that are not claimed, and responsible reporting.
- Effective
- 2026-08-10
- Last updated
- 2026-08-10
- Version
- 2026-08-10
Implemented safeguards
sexxWise uses Firebase Authentication, HTTP-only server sessions, owner-scoped Firestore rules, server-only writes for sensitive collections, separate Together reveal rules, server-only billing and AI credentials, data minimization, Privacy Mode, Discreet Mode, raw export, and scoped deletion.
App Check
A Firebase App Check site key is configured. Deployment enforcement and monitoring still require operational verification.
Controls sexxWise does not claim
sexxWise does not claim end-to-end encryption, zero-knowledge architecture, encrypted private-note fields, perfect security, bank-level or military-grade security, a formal security certification, or an active bug-bounty program.
User security and privacy controls
Users can sign out, use Privacy and Discreet modes, hide Explore navigation, withdraw optional adult-content access, delete scoped data, export raw data, and request account deletion. Sensitive-section reauthentication and session management are not represented as complete until fully wired.
Responsible vulnerability reporting
Send a clear description, affected URL, reproduction steps, and impact to support@sexxwise.com. Do not access another person's data, disrupt the service, use social engineering, publish unresolved sensitive details, or demand a bounty. sexxWise does not promise payment.
Security incidents
sexxWise maintains an internal incident-response draft covering detection, containment, data-category assessment, provider coordination, jurisdiction analysis, notification, documentation, and special handling of health and sexual-wellness data. The operational procedure requires security, privacy, and legal review.