SECURITY

Minimize authority. Preserve evidence.

Euphoric Doom is building around least privilege, explicit authorization, bounded testing, fail-closed cost controls and evidence-backed operations.

Initial security posture.

Authorization. Test Flight work is limited to systems and artifacts the client is authorized to provide.

Secrets. Credential inventories store metadata and secret locations—not secret values in public business records.

Payments. Card data is intended to remain with Stripe-hosted checkout rather than Euphoric Doom infrastructure.

Cost controls. Paid-plan activation and autonomous spending require explicit approval.

Customer data. Collection should be limited to what the agreed engagement requires.

Incidents. Operational incidents are intended to preserve evidence, identify affected resources, record corrective actions and produce regression tests where appropriate.

Report a security issue.

If you believe you found a security issue in a Euphoric Doom property, contact euphoricdoom@gmail.com. Please avoid accessing data that is not yours, disrupting service, or testing third-party systems without authorization.

A security report does not create a bug-bounty payment obligation unless a written bounty program or agreement explicitly says otherwise.