Security
Last updated: July 25, 2026
You hand us a credit report. That file lists your accounts, balances, addresses, and the last four of your Social Security number. This page describes, in plain terms, what we do to protect it — and what we deliberately do not claim.
Data in transit
Every connection to creditcougar.com is served over HTTPS with 256-bit TLS. Plain HTTP requests are redirected to HTTPS before any content is served. Certificates are issued by Let's Encrypt and renewed automatically.
Data at rest
Uploaded credit reports and Document Vault files are stored encrypted at rest on our own infrastructure. Parsing happens on our server — your report is never forwarded to the credit bureaus by us, never sold, and never shared with an advertising network.
We store the last four digits of your Social Security number, never the full number.
Passwords and sessions
- Passwords are hashed with bcrypt (cost factor 10). We never store, log, or email your password, and we cannot read it.
- Sessions use a server-side store. The session cookie is
HttpOnly(unreadable by JavaScript),Secure(HTTPS-only), andSameSite=Lax. - Login, password-reset request, and password-reset submission endpoints are rate limited per address and per IP to blunt credential stuffing.
- Password-reset links are single-use, expire after 60 minutes, and are stored only as a SHA-256 hash. Completing a reset signs out every existing session for that account.
Payments
Card details are entered on Stripe-hosted Checkout, not on our pages. Card numbers never touch our servers, our logs, or your browser's storage on our domain. We retain only Stripe's customer and subscription identifiers.
Access control
Every credit report, tradeline, dispute letter, campaign, Vault document, and chat message is scoped to the account that created it. Requests for a record you do not own are rejected, whether or not you can guess its identifier. Signing out invalidates the session server-side, not just in your browser.
What we do not claim
We think security pages should be honest about their limits:
- CreditCougar has not completed a SOC 2, ISO 27001, or PCI DSS audit. Card handling is delegated to Stripe, which is PCI Level 1 certified; that certification is Stripe's, not ours.
- We do not offer multi-factor authentication yet.
- No system is perfectly secure. If we discover a breach affecting your data, we will notify you within the window your state's breach-notification law requires (typically 30–60 days).
Your controls
- Delete an uploaded report at any time from the dashboard; its parsed tradelines go with it.
- Delete individual Document Vault files at any time.
- Export everything we hold about you from
Settings → Export my data. - Request a hard delete of your account and all associated data by emailing support@creditcougar.com with subject Delete my account.
Reporting a vulnerability
If you believe you've found a security issue, email support@creditcougar.com with subject Security report. Please include steps to reproduce. We will acknowledge within 3 business days. Please do not run denial-of-service tests, automated bulk scanning, or any test that touches another customer's data.
See also our Privacy Policy and Terms of Service.