Security

Security at Suroda

Last updated: August 4, 2026

Suroda builds forensic detection technology; we take the same discipline to the systems that operate our website, app, portal, media pipeline, and evidence-support workflows.

Safeguards

Transport. Suroda web and app traffic is served over HTTPS with TLS certificates managed by our hosting and cloud providers.

Identity. Account access is handled through Firebase Auth and authenticated application flows. Users should keep their devices, email accounts, and passwords secure.

Storage. Account records, job metadata, uploaded media, and generated evidence-support records may be stored in Google Cloud and Firebase services, including Firestore, Cloud Storage, and Cloud Run/API-backed workflows.

Payments. Web payments are processed by Stripe. Card data is handled by Stripe and does not pass through Suroda card-storage systems.

Access. Administrative access is restricted to operational personnel and service accounts with a business need. We use authenticated access and least-privilege practices where practical.

Data minimization. We aim to collect and retain only what is needed to provide, secure, review, and support the service, subject to legal holds, evidence custody, payment, tax, accounting, security, and compliance obligations. See our Privacy Policy and Account Deletion page.

Evidence-support records. Hashes, custody records, processing lineage, and matter-linked records may be retained to preserve integrity and reviewability. See Evidence and Chain of Custody.

Operational security. We do not publish detailed internal architecture, credentials, private network layout, or detection implementation details on the public website.

Reporting a vulnerability

If you believe you've found a security issue on suroda.com, portal.suroda.com, or the Suroda app, email hello@suroda.com with details. We ask that you give us reasonable time to remediate before public disclosure, and we won't pursue good-faith researchers who avoid data destruction, privacy invasion, service disruption, or public disclosure before we have had a reasonable opportunity to investigate.