1. Security
At NameToProfile, we take a practical, risk-based approach to protecting customer data, account data, and service operations.
2. Security Overview
We use a combination of administrative, technical, and organizational measures designed to help protect the confidentiality, integrity, and availability of the Service.
Our security measures are intended to reduce risk, support reliable operation, and protect against unauthorized access, misuse, and accidental loss. However, no system can be guaranteed to be completely secure.
3. Security Program Areas
Key elements of our security program may include:
- Access Control: limiting access to systems and data to authorized personnel and service components that require access for legitimate operational purposes.
- Data Protection: protecting data in transit and at rest using appropriate safeguards based on technical feasibility, system design, vendor capabilities, and risk.
- Application and Infrastructure Security: dependency maintenance, patching, monitoring, logging, abuse prevention, rate limiting, environment separation where appropriate, and secure configuration management.
- Add-in Security: operating within Google and Microsoft permission models and requesting only the access reasonably needed for the intended feature.
- Incident Response: internal processes to identify, investigate, contain, and respond to suspected security incidents.
- Vendor and Platform Dependence: security also depends in part on the security and availability of hosting, email, payment, Google, and Microsoft environments.
4. Customer Security Responsibilities
Customers also play an important role in security. You are responsible for safeguarding account credentials, using strong passwords and appropriate access controls, limiting who can access your spreadsheets, workbooks, and uploaded files, ensuring lawful and appropriate submission of Customer Data, reviewing outputs before relying on them, and promptly notifying us of suspected unauthorized access or security issues.
5. Responsible Disclosure
If you believe you have found a security issue relating to NameToProfile, please contact us at info@nametoprofile.com. Please include reasonable details to help us understand and investigate the issue.
Please do not perform intrusive testing, denial-of-service activity, destructive testing, data extraction, social engineering, or any activity that could harm the Service, our users, or third parties without our prior written authorization.
6. No Certification Claim
Unless expressly stated by us in writing, we do not claim that the Service is certified under any specific audit, security, or compliance framework.
7. Updates
We may update this Security page from time to time to reflect product, operational, or legal changes.