Security

Modern controls,
quietly working.

This page is maintained by the PetSenseAI team to answer common security and privacy questions about the product. It describes the controls we operate today and is not a certification.

Effective August 3, 2026Last updated August 3, 2026PetSenseAI, Inc.

Program overview

PetSenseAI is maintained by the PetSenseAI team to answer common security and privacy questions about the product. This page describes the controls we operate today. It is not a certification or an independent audit report.

Security is a shared responsibility: PetSenseAI operates the platform controls below, and account holders are responsible for protecting their credentials, choosing what to upload, and complying with these Terms.

Authentication

Sign-in is powered by managed authentication with hashed credentials, short-lived access tokens, and refresh rotation. Google single sign-on is supported. Sessions are bound to the browser origin and cleared on logout.

Data protection

Data is encrypted in transit with TLS 1.2 or higher. Data at rest is encrypted with provider-managed keys. Database access uses row-level security so a signed-in user can only reach records their account owns.

Access controls

Production access is limited to authorized engineers. Administrative operations are logged. Long-term secrets are rotated on schedule and after any suspected exposure.

Sub-processors

We use audited third-party providers for infrastructure, storage, email, analytics, payments, and AI. Each provider is bound by a written data protection agreement. A current list of categories appears in the Privacy Policy.

AI safety

AI providers process scan and chat inputs to generate a response. Contractual terms prohibit use of your inputs to train foundation models. AI outputs are educational and not a substitute for veterinary care.

Backups and recovery

The primary database is backed up on a rolling schedule with point-in-time recovery. Deletions are honored in live systems within 30 days and expire from backups on the standard backup cycle.

Vulnerability disclosure

We welcome reports from security researchers and the wider community. If you believe you have found a security issue, email security@petsenseai.com with a clear description, reproduction steps, affected URLs, and any proof-of-concept material. PGP is available on request. Our machine-readable policy is published at /.well-known/security.txt in line with RFC 9116.

What to expect: we acknowledge new reports within 2 business days, provide an initial triage assessment within 5 business days, and send status updates at least every 10 business days until the issue is resolved. Please give us reasonable time to remediate before public disclosure. We will not pursue good-faith researchers who follow this policy, and we are happy to credit reporters in our acknowledgments once a fix has shipped.

Out of scope: denial-of-service testing, social engineering of our staff or users, physical attacks, automated scanner output without a working proof of concept, and issues in third-party services we do not operate.

Incident response

We investigate reports and confirmed incidents on a documented runbook. When required by law, we notify affected users of a confirmed personal data breach without undue delay.

Questions?

Reach us at hello@petsenseai.com. For privacy requests write to privacy@petsenseai.com. For security disclosures write to security@petsenseai.com.