Skip to content
FlatspecGarment spec sheets

Security

Unreleased design work needs treating like it

The files here are commercially sensitive before they are anything else. This page states what we do about that, in terms you can check rather than adjectives you cannot.

We are deliberately not making superlative claims. No system is unbreakable and anyone telling you otherwise is selling something. What follows is what is actually in place.

Fixed on the upload screen

Your designs stay yours. We don't train on them, we don't show them to anyone, and we don't use them in our own marketing. You can delete them or take them with you at any time.

01Payments

We never see your card

Card details are entered on a page hosted by our payment provider, which is certified as a PCI DSS Level 1 service provider. They never pass through our servers.

  • Every page served over HTTPS with HSTS, including preload
  • Card entry hosted by our PCI DSS Level 1 payment provider
  • 3-D Secure applied where the card issuer requires it
  • We receive only the card brand, last four digits and charge status
  • We never receive full card numbers
  • We never store card numbers, expiry dates or security codes
  • We hold no funds on behalf of you or any supplier
  • No card details are ever sent to our inference provider

Cards accepted

  • Visa
  • Mastercard
  • American Express

All charges are in USD. Your issuer may add its own conversion or cross-border fee, which we do not see and cannot refund.

02Your files

What happens to a design after you upload it

  1. 01

    In transit

    TLS 1.2 or better, with modern cipher suites only. Requests over plain HTTP are redirected before anything is sent.

  2. 02

    At rest

    Encrypted on disk, in a database hosted in the European Union, with encrypted backups.

  3. 03

    During generation

    Sent to the inference provider named in the privacy policy, over TLS, for the single purpose of producing the output you asked for. The provider is contractually prohibited from retaining it for training.

  4. 04

    While stored

    Reachable only by your account. Read-only sharing links are unguessable, expire, and can be revoked by you at any time.

  5. 05

    When you delete

    Removed from the live system immediately and from backups within 30 days. Closing the account deletes everything within 30 days.

  6. 06

    Never

    Used to train or fine-tune any model. Used in our marketing, examples or portfolio — including anonymised. Sold or disclosed to anyone else.

Line drawing of a closed document folder with a padlock resting on it, enclosed by a thin red boundary line.
The training prohibition is written into the Content Licence as a limit on what we are permitted to do, not as a preference we can revisit.

03Platform

The rest of it

Access control

Production access is limited to the people who need it, requires multi-factor authentication, and is logged.

Response headers

HSTS with preload, X-Content-Type-Options, X-Frame-Options DENY, a strict Referrer-Policy and a restrictive Permissions-Policy on every route.

Passwords

Hashed with a memory-hard algorithm. We cannot read yours and will never ask for it — no member of our team will ever request it by email or phone.

Form protection

Public forms are rate limited and protected against automated abuse. Every submission is validated again on the server.

Breach notification

If a breach is likely to risk your rights we notify the ICO within 72 hours of becoming aware, and tell affected users without undue delay.

Reporting a problem

Email support@orasci.shop with the details. We will acknowledge within 2 business days, and we will not pursue anyone who reports a genuine issue in good faith and does not exploit it.

Privacy policy, including the full processor list