Version 2026-09-06 · Effective 6 September 2026
Platform controls
- Hashed account passwords and encrypted HTTPS transport.
- Authenticated, role-controlled and subscription-controlled routes.
- Cross-site request forgery protection and request rate limits.
- Verified PayPal webhook signatures and no storage of complete payment credentials.
- Workspace content excluded from the normal RCET application database.
- AES-256-GCM encrypted local continuation files using a user-supplied password.
- Optional AI is disabled unless separately configured and requires a deliberate user request.
User responsibilities
- Use a unique password of at least 12 characters and secure the registered email account.
- Sign out on shared devices and keep operating systems and browsers updated.
- Store local case files only on an approved encrypted drive and protect the file password separately.
- Do not share accounts, files or passwords and do not send sensitive material in support emails.
- Report suspected compromise promptly and stop using the affected device or account.
Incident reporting
Report a suspected account or platform incident to contact@cuttingedgetools.xyz. Provide the time, affected account and observable symptoms, but do not include live case content or credentials.
No absolute guarantee
Security reduces risk but cannot eliminate it. RCET will continue testing, patching and improving controls and will assess notification obligations if a personal-data breach is confirmed.