Legal

Security Policy

Last updated July 7, 2026

Our commitment

SlopMotion is built for live performance. We design for availability, but we also treat account data, creator assets, and payment flows with care.

Infrastructure

The Service runs on managed cloud infrastructure with encryption in transit (TLS) for web and API traffic. Database and object storage are hosted with established providers and access-controlled.

Authentication

Passwords are handled by our authentication provider; we do not store plaintext passwords. Session cookies use secure, HTTP-only settings appropriate to our domains.

Use a strong, unique password and sign out on shared machines.

Access controls

Production access is limited to team members who need it. Administrative tools are separate from the public app and protected by role-based access.

Monitoring and incidents

We monitor for abuse, anomalous sign-in patterns, and service errors. If we become aware of a security incident affecting your data, we will investigate promptly and notify affected users or regulators where required by law.

Reporting vulnerabilities

If you discover a security issue, report it responsibly to hey@slopmotion.cool. Please include enough detail for us to reproduce the issue. Do not publicly disclose before we have had a reasonable chance to respond.

Your responsibilities

Keep credentials private, review connected devices, and contact us immediately if you suspect unauthorized access to your account.