Key Points
- Auric Artisan protects account, session, billing, API, and tool traffic where those features are enabled
- Security practices cover color science tools, web analysis, theme generation, palettes, and visual simulations
- Web analysis tools must only be used on websites and digital assets you own or are authorized to test
- Security checks in web analysis are informational and are not a certified audit or penetration test
- We aim to minimize collection, processing, and retention of submitted URLs, reports, and technical metadata
- No system can guarantee perfect security; controls and practices will evolve as infrastructure matures
1. Security Principles
+Auric Artisan is designed around practical security, privacy, and responsible use. Security controls are intended to protect the platform, its tools, user-submitted inputs, generated outputs, and the supporting infrastructure as the service evolves.
- Minimization — Collect and process only what is needed for tool operation
- Least privilege — Restrict internal access to systems, logs, and generated data
- Responsible tooling — Keep web analysis useful without encouraging unauthorized testing
- Secure evolution — Improve controls as account, paid-service, and production infrastructure evolves
2. Current Infrastructure Status
+Auric Artisan provides and develops tools for color science, color-related articles and learning resources, web analysis, theme generation, palette workflows, and visual simulations, including 70+ vision simulation models and multiple color science models.
Pricing pages, plan information, account features, billing pages, and API-key pages may appear on the website depending on rollout status. Paid subscriptions and checkout payments are valid only through official live checkout flows.
3. Data and Transmission Security
+Where Auric Artisan processes submitted data, such as URLs, page metadata, screenshots, palette inputs, generated themes, reports, or tool outputs, we aim to handle that data with reasonable technical and organizational safeguards.
- Use encrypted transport for browser-to-service communication where network processing is required
- Limit access to submitted inputs and generated reports to operational needs
- Avoid collecting unnecessary personal data for color tools, simulations, and web analysis workflows
- Protect signed-in auth requests with secure, HttpOnly session cookies and CSRF verification where applicable
- Apply origin checks, request-size limits, security headers, and route-specific rate limits on auth endpoints
- Use local browser storage where practical for preferences such as theme, layout, and eye-rest settings
- Review retention practices as backend infrastructure and account features mature
Some tools may run partly in the browser and may rely on local storage, cookies, or temporary processing data. Details are provided in the Privacy Policy and Cookie Policy.
4. Web Analysis Security Scope
+Auric Artisan’s web analysis tools may inspect website structure and signals related to security, performance, responsive design, palette extraction, theme generation, accessibility, metadata, and Lighthouse-like quality checks.
These tools are intended for analysis of websites, pages, and digital assets that you own, control, operate, or have explicit permission to test.
- Do not use web analysis tools to probe, scan, stress, bypass, or exploit third-party systems without authorization
- Do not use results as proof of compliance, certification, or a completed security audit
- Do not submit private URLs, credentials, admin pages, confidential dashboards, or sensitive internal systems unless you are authorized and understand the risk
- Do not use generated reports to misrepresent the security posture of another website or organization
5. Access Control and Internal Practices
+Internal access to systems, deployment workflows, logs, and configuration should be limited to authorized maintainers and used only for operation, security, debugging, and platform improvement.
- Restrict administrative access where technically feasible
- Use separate development and production workflows as infrastructure matures
- Avoid exposing secrets, keys, tokens, or private configuration in public code or client-side assets
- Review dependencies, scripts, and third-party integrations for security and privacy impact
6. User Responsibility
+Users are responsible for using Auric Artisan safely and lawfully. This includes:
- Submitting only content, URLs, files, or website data that you are allowed to analyze
- Keeping sensitive credentials, private tokens, and confidential URLs out of tool inputs unless required and authorized
- Checking generated outputs before relying on them in design, development, accessibility, or security workflows
- Using Ishihara-style and vision simulation tools only for exploration, design, and learning
- Reporting suspected security issues responsibly instead of attempting unauthorized access
7. Limitations and Non-Certification
+No website, platform, or analysis tool can guarantee absolute security. Auric Artisan makes reasonable efforts to protect the platform, but unauthorized access, data loss, errors, downtime, or security issues may still occur.
Color science models, theme generation, palette extraction, responsive previews, performance checks, and visual simulations are provided for analysis, creativity, and exploration. They are not certified industrial, medical, regulatory, or safety-critical systems.
8. Vulnerability Reporting
+If you discover a suspected vulnerability, misconfiguration, exposed secret, or security weakness, please report it through the contact page with enough detail to help us reproduce and understand the issue.
Please do not access, modify, delete, download, or disclose data that does not belong to you. Reports should be made in good faith and should avoid disruption to the platform or third-party services.
9. Security Incidents
+If a security incident is identified, Auric Artisan may take steps to investigate, contain, remediate, and communicate the issue based on its severity, legal obligations, and available contact channels.
- Investigate the scope and likely impact of the incident
- Limit further exposure where practical
- Apply fixes, patches, configuration changes, or access restrictions
- Notify affected users or authorities where required by applicable law
10. Changes to This Policy
+This Security Policy may be updated as Auric Artisan’s infrastructure, tools, account access, paid services, web analysis capabilities, and security practices evolve. Material changes may be communicated through the platform where practical.