Security
Where to find what Parse does, what it does not do, and how to tell us when it is wrong. Detection reduces risk; it does not replace least-privilege tools or output validation.
Documents
- Security limitations — what Parse screens, what it misses, and the failure modes we know about. Read this before you design around Parse.
- Trust and security — architecture, security controls, subprocessors, what we store and for how long, and compliance posture.
- Vendor security questionnaire — the 30 most-asked assessment questions, pre-answered.
- Privacy policy — what we collect, what we store per endpoint, and where prompt text travels.
- Changelog — what changed and when.
Reporting a vulnerability
Email [email protected]. We acknowledge reports within 48 hours and aim to remediate critical findings within 90 hours. We will not pursue legal action against researchers who respect user privacy, avoid denial of service and social engineering, report promptly, and give us reasonable time to fix the issue before disclosing it. Full policy and remediation targets are on the trust page.
For abuse or denial-of-service reports, use [email protected]. For everything else, use support.
Machine-readable
GET /v1/security/headers— the security headers this deployment setsGET /status— running build and dependency stateGET /security/limitationswithAccept: text/markdown— the limitations document as source markdown