Security

Last updated 9 September 2026

This page describes how the Peripatetical services — CloudMonitor and Grocery Concierge — protect the data you give them. It is written to be checkable rather than reassuring: everything below is either in place today or explicitly named as not in place.

If you only read one paragraph: this is a small, carefully built platform run by one person. The security work is real and deliberate, but it is sized for a service that is not yet handling anyone's production secrets at scale. Where that shows, this page says so.

How your account is protected

Sign-in

All sign-in goes through one central identity service rather than each product keeping its own passwords. In practice that means:

Where your data sits

Who can see it

Payments

Payments are handled entirely by Stripe, which acts as merchant of record. Card numbers are never sent to, processed by, or stored on Peripatetical systems — there is no payment form in this codebase to leak them from.

How the platform is maintained

What is deliberately not in place

Every service has gaps. Most security pages omit theirs. Here are the ones that would matter to you, and why they are where they are:

These are cost and scale decisions, not oversights, and each is written down and tracked. They are reviewed as the services grow — but you are entitled to know the state today rather than the intention.

What is being built right now

Listing this separately rather than describing it as done, because as of the date at the top of this page it is written and reviewed but not yet running in production:

This section shrinks as each item ships, and the date above moves when it does.

If something goes wrong

If personal data is ever compromised, the commitment is specific rather than vague:

Reporting a vulnerability

If you find a security problem, please report it through the support form and say clearly in the message that it is a security issue — that routes it straight to the operator.

Please give a reasonable window to fix it before disclosing publicly. Good-faith research is welcome, and reports are read by a person, not a queue. What is asked in return: do not access, modify, or delete data that is not yours, do not degrade the service for other people, and do not use automated scanning heavy enough to look like an attack.

There is no paid bug bounty. This is a pre-revenue project and pretending otherwise would waste your time.

Changes to this page

If a control described here is turned off or materially changed, this page changes with it and the date above moves. It is meant to describe the service as it actually is, not as it was intended to be at launch.