Last updated
Security policy
The safeguards built into Citation, the limits of those safeguards, and how to report a security concern.
Draft for review. The operator’s service address and applicable jurisdiction still need confirmation before publication. Contact hello@alptekincan.com with questions.
On this page
Scope and approach
RELOAD TECHNOLOGIES - FZCO operates Citation. This policy describes safeguards implemented in the application and a contact route for security concerns. It is intended to help you make informed decisions about your account, your documents, and the features you use.
Application controls are one part of security. Their effectiveness also depends on deployment configuration, provider operations, and how people use the service. This document is not an independent audit report, a certification, or a guarantee that incidents cannot occur. Data processing is explained separately in the Privacy policy.
Account and document access
Citation uses Supabase for authentication. Private application routes check the signed in user and relevant permissions. Database policies and server checks restrict access according to workspace membership, document invitations, ownership, and assigned roles. Sensitive server operations use credentials kept outside the browser.
Account controls include password management and a way to revoke other sessions. Password recovery uses a protected, time limited verification flow. Revoking refresh sessions does not necessarily invalidate every access token immediately; an existing token can remain valid until its normal expiry.
Document access and workspace access are distinct. A guest invited to a document is not automatically a member of every workspace containing related material. A public link intentionally allows the shared view to be read without signing in. Treat the link as an access credential and review the source details included in that view before sharing it.
Application safeguards
The application includes validation of supported inputs, account and provider usage budgets, file and request size limits, and checks on permissions before protected operations. File processing restricts supported formats and bounds resource use. Public source retrieval validates destinations and limits responses to reduce exposure to unsafe requests.
Private responses use controls intended to prevent shared caching. Browser security headers restrict framing, content type guessing, and certain device permissions. The Microsoft Word companion has a narrow framing exception for supported Office hosts. These measures reduce specific risks; they do not make uploaded files or external sources inherently trustworthy.
Configured account integrations protect stored credentials with application encryption and require server configuration before they can be used. This specific safeguard should not be interpreted as a claim that every document is encrypted with a key controlled only by its author.
Infrastructure and providers
The hosting design uses Vercel, with Supabase for authentication, database records, and file storage. Server connections to the configured cloud providers use HTTPS. The security of stored data and provider infrastructure also depends on the settings and contractual arrangements for those services.
AI and voice features send content through OpenRouter to the relevant model or speech provider. Similarity search also uses an external search provider. Using these features necessarily gives the providers the content needed to process the request. Citation therefore does not offer encryption that prevents all service providers from reading content during processing.
We do not claim SOC 2 or ISO certification, independently verified penetration testing, a guaranteed backup recovery time, a fixed incident response deadline, or a service availability commitment. Data regions, provider retention, and operational recovery procedures must be confirmed separately before any such commitment is made.
Protecting your work
- Use a unique password and protect the email account or identity provider you use to sign in. Do not disclose a password, verification code, or recovery link to another person.
- Check recipient addresses and access roles before inviting someone. Restrict public links when they are no longer needed, and review workspace membership regularly.
- Only connect tools you recognise. Review the requested permissions and revoke unused connections in Citation and, where appropriate, in the provider’s settings.
- Keep your browser and device updated. On a shared device, sign out and use browser controls to remove residual site data after confirming that your work has saved.
- Keep independent exports of important documents. Check imported files, citations, and external links before relying on them.
Citation can keep unsynced editing state in local storage to help recover interrupted saves. That state may contain document content. A shared computer, browser extension, or someone with access to your browser profile may be able to access it. See the browser storage explanation before clearing data or working on an untrusted device.
Reporting a vulnerability
Send suspected Citation security issues to hello@alptekincan.com with the subject “Citation security report.” This uses the existing service contact; no separate security portal or public bounty programme is currently offered.
A useful report includes the affected page or feature, a description of the possible impact, the approximate time observed, and the smallest set of steps needed to reproduce the issue using an account or data you control. Include relevant browser details and a redacted screenshot or short example when helpful.
Do not send passwords, live access tokens, private invitation links, or copies of someone else’s documents. If a report needs sensitive evidence, describe what you have and request a suitable transfer method first. Please allow a reasonable opportunity for the issue to be assessed and addressed before publishing details that could expose users.
Responsible research boundaries
Use your own accounts and content, or obtain explicit permission from the person entitled to authorise the test. Keep activity proportionate and stop when you have enough evidence to describe a suspected issue. If you unexpectedly encounter another person’s information, stop accessing it and report the exposure without copying or changing the material.
Do not use social engineering, phishing, credential guessing, destructive actions, service disruption, persistent access, or bulk extraction of data. Do not test a provider’s infrastructure merely because Citation uses it. A report to Citation does not authorise testing of Supabase, Vercel, an AI provider, or another external service.
This reporting policy is not a blanket testing authorisation, a promise of legal immunity, or an offer of payment. If a proposed test could affect other people or service availability, request written scope and permission before proceeding.
If you suspect an incident
If your account may be compromised, secure your sign in method, use the session controls, review sharing and connected services, and contact us promptly. Tell us which account and features are affected without including secrets. If possible, retain relevant dates and error references rather than making repeated attempts that could worsen the issue.
A response may involve investigating available records, limiting access, disabling a feature, revoking affected permissions, or working with a provider. Any notification to affected people or authorities must follow applicable legal requirements. This policy does not promise a specific acknowledgement time or resolution deadline.
We will update this policy when relevant safeguards or reporting arrangements change. The date above identifies the latest version. For privacy requests or deletion questions, use the process in the Privacy policy.
Questions about this policy? hello@alptekincan.com
Back to top