Security Policy

Last updated: July 22, 2026

Kreatorly takes the security of your account, content, and payment information seriously. This Security Policy outlines the measures we take to protect the platform and what you can do to help keep your account safe.

1. Data Encryption

All traffic between your device and Kreatorly is encrypted in transit using industry-standard TLS. Passwords are never stored in plain text — they are hashed using a modern, one-way hashing algorithm before being saved.

2. Payment Security

Kreatorly does not store full card numbers on its own servers. Payment transactions are processed through PCI-compliant third-party providers, including eSewa, Khalti, connectIPS, and Stripe for diaspora payments. Sensitive payment details are handled entirely within these providers' secure infrastructure.

3. Content & Media Security

Videos and media files are stored and streamed through Bunny.net (Bunny CDN), a third-party content delivery provider. Access to membership-gated content is restricted to verified, active subscribers through authenticated delivery URLs.

4. Creator Verification Document Security

Creator payout onboarding requires identity and banking documents (such as PAN card and citizenship images) for verification purposes. These documents are stored in a private, access-controlled storage environment separate from public content storage, and are only ever accessed through short-lived, presigned URLs rather than being served as public files. Access is restricted to what's needed for payout verification and fraud prevention.

5. Access Controls

Internal access to user data and platform infrastructure is limited to authorized personnel on a need-to-know basis. We apply role-based access controls across our systems and regularly review access permissions.

6. Account Security Recommendations

To help keep your account secure, we recommend:

  • Using a strong, unique password not reused from other services
  • Avoiding sharing your login credentials with anyone
  • Logging out of shared or public devices after use
  • Contacting us immediately if you notice suspicious account activity

7. Incident Response

If we become aware of a security incident that affects your personal information, we will take reasonable steps to investigate, contain, and remediate the issue, and notify affected users as required by applicable law.

8. Reporting a Vulnerability

If you believe you've discovered a security vulnerability on Kreatorly, please report it responsibly to security@kreatorly.com rather than disclosing it publicly. We appreciate good-faith reports and will respond as promptly as possible.

9. Changes to This Policy

We may update this Security Policy as our practices and infrastructure evolve. Material changes will be reflected here with an updated revision date.

10. Contact Us

Security-related questions or reports can be sent to security@kreatorly.com.

If you have questions about this Security Policy or want to report a concern, please contact us at [security@kreatorly.com](mailto:security@kreatorly.com).