---
title: "Security - Azurade AI"
description: "How Azurade AI secures your account and data, and how to report a vulnerability."
canonical: https://azurade.com/security/
---

[](https://azurade.com/)

# Security

Last updated: September 1, 2026

Azurade AI is built and operated by Dubir Group LTD. This page summarises how we secure the Service and your account, and how to report a vulnerability.

## 1\. Encryption in transit

All traffic to Azurade AI is served over HTTPS (TLS). Requests over plain HTTP are redirected to HTTPS, and we send HTTP Strict Transport Security (HSTS) so browsers refuse to connect insecurely.

## 2\. Authentication & passwords

You can sign in with Google, in which case we never handle a password for you. Where a password is used it is never stored in plain text — we keep only a salted hash, and no one at Dubir Group LTD can see it. Sessions use bearer tokens.

## 3\. Access control & data isolation

Every account's data is scoped to that account. One user cannot read or write another user's prompts, generated content, or account data. Requests for data you do not own are rejected server-side, not just hidden in the interface.

## 4\. Payments — we never touch your card

Subscription and credit billing is handled by Creem.io, our merchant of record, on PCI-DSS-certified payment infrastructure. Card details are entered on Creem's hosted checkout, so full card numbers never reach or get stored on our servers. Payment webhooks are verified by cryptographic signature before we act on them.

## 5\. Model inference

Your Prompts and input images are sent to third-party model providers to generate your content. Results are returned to us over signature-verified webhooks. We do not use your personal data or your unique content to train models without your consent.

## 6\. Infrastructure & backups

The Service runs on managed cloud infrastructure with access restricted to authorised operators. We take regular backups so your data can be recovered, and we apply security updates to our dependencies on an ongoing basis.

## 7\. Your data is yours

You can export your gallery and delete your account at any time. We do not sell your data. See the [Privacy Policy](https://azurade.com/privacy-policy/) for how personal data is handled and your rights under GDPR.

## 8\. Breach notification

No system is perfectly secure. If a personal-data breach affecting you occurs, we will notify you and the relevant supervisory authority as required by GDPR and applicable law.

## 9\. Reporting a vulnerability

We welcome responsible disclosure. If you believe you have found a security issue, email legal@azurade.com with the details and steps to reproduce. Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly, and avoid accessing or modifying data that is not yours. We are grateful for reports made in good faith.

## 10\. Contact

Security questions or reports: legal@azurade.com.
