Security Policy

1. Our Security Commitment

MrInvoice.APP handles your business's billing records, so security is foundational to how we build and operate the Service. This policy describes our security practices and our responsible disclosure program.

2. Site and Service Security Measures

Encryption in transit

All traffic to mrinvoice.app is encrypted via HTTPS/TLS, terminated at Cloudflare's edge and carried to our infrastructure over an encrypted tunnel.

Sign-in protection

No third-party tracking

The Site does not load third-party analytics scripts, advertising pixels, or social media trackers. Only strictly necessary session cookies are set.

Infrastructure

The Site is served through Cloudflare's edge network, which provides built-in DDoS mitigation, WAF protection, and bot management. Our application servers are not directly reachable from the internet.

3. Data Security

4. Responsible Disclosure

We welcome security researchers who identify vulnerabilities in our website or the Service. We are committed to working with the security community to address issues quickly.

How to report

Use our contact form and mention "Security Disclosure" in your message. Please include:

Our commitments to researchers

What we ask of researchers

5. Legal Safe Harbor

MrInvoice.APP will not initiate legal action against security researchers who discover and report vulnerabilities in good faith, consistent with these guidelines. We consider good-faith security research to be authorized and will work with researchers rather than against them.

6. Contact

Security disclosures: use our contact form — mention "Security Disclosure".