This page describes the technical and organizational measures Short Form Nation, Inc., doing business as SFN AI, uses to protect the data processed through the SFN AI platform and services. It also tells you how to reach us about anything security related.
This page is a description of practice. It is not a contract and it does not create rights. It states what is true today. Where a control is not in place, this page says nothing about it rather than describing an intention as a control.
What we collect, why, how long we keep it and what rights you have are covered in our Privacy Policy. Tracking technologies are covered in our Cookie Policy. The vendors that process data for us are listed on our Sub-processors page. This page does not repeat any of them.
SFN AI maintains a written information security program. It is a set of adopted policies and procedures covering the systems that hold customer and creator data, and it is owned by our CTO. Every document below was adopted on 6 August 2026.
| Document | What it covers |
|---|---|
| Information Security Policy | Baseline posture, ownership, systems in scope, review cadence |
| Network Security Policy | How access to production systems is restricted, and how those rules are reviewed |
| Endpoint Protection Policy | Controls required on any device that can reach production credentials or data |
| Access Control Policy | Least privilege, credential rules, access review, offboarding |
| Data Classification and Encryption Policy | Which data counts as personal data, and how each tier is encrypted |
| Incident Response Policy | Roles, escalation path, reporting channels, response steps |
| Vulnerability and Threat Management Procedure | How vulnerabilities are found, triaged and remediated |
| Data Retention and Deletion Procedure | What is deleted at the end of a relationship, and how fast |
| Breach Notification Procedure | Who is notified, by whom, and how quickly |
The program is reviewed at least annually, and immediately after any confirmed security incident, any material change to our production network, or the onboarding of anyone new with production access. The next scheduled review is 6 August 2027.
Security is a shared responsibility. We protect the platform. You are responsible for using strong, unique credentials, for keeping your account access confidential, and for the activity that happens under your account. If you suspect unauthorized access, tell us at security@shortformnation.com without delay.
In transit. All public endpoints enforce TLS 1.2 or higher. Traffic between you and SFN AI is encrypted over the public internet, and administrative access to our cloud provider runs over TLS as well.
At rest. Our production database storage is encrypted at rest using AES-256. The queues that carry operational data between our services are encrypted with managed keys held in AWS Key Management Service. We use provider-managed keys, which removes a class of key handling risk rather than adding one.
Our Data Classification and Encryption Policy sets the standard those controls meet. It names which fields count as personal data, which count as de-identified or aggregated, and which are purely operational, and it requires personal data to be encrypted at rest with AES-256 or equivalent and transmitted only over TLS 1.2 or higher.
SFN AI runs on Amazon Web Services. Our application, database, queues and processing jobs all run in the AWS Frankfurt region. Our marketing website is hosted on Netlify. The physical, network and environmental controls in those data centers are the providers' own, are described in the providers' compliance documentation, and are not ours to represent.
We do not claim a segmented network architecture. Our Network Security Policy sets that as the target state and the work to get there is scheduled, not finished. We would rather tell you what is running today than describe a plan as a control.
We have a written Access Control Policy. Access to production systems and to personal data is granted per named individual, scoped to the minimum permissions the role requires, and reviewed.
Security checks are enforced automatically on every change, by machines rather than by memory. Our continuous integration pipeline blocks a pull request that violates any of them.
We treat these as security controls and not only as performance controls, because each of them has caused a real production failure in the past. We patch dependencies and infrastructure in response to known vulnerabilities.
We have a written Vulnerability and Threat Management Procedure. It defines the code level controls described above, the remediation severity bands we work to, and the retention period for findings.
Being direct about the limits of this: we do not currently run continuous automated vulnerability scanning across our cloud infrastructure. That is a scheduled item, not a finished one, and until it is running we would rather leave the sentence off this page than describe it in softer words.
We have a written Incident Response Policy with named roles, an escalation path and defined response steps. Our CTO is the incident commander and owns triage, containment, remediation and the decision to communicate externally.
Breach notification. If there is a breach of security leading to unlawful or unauthorized access to, acquisition, disclosure, loss or destruction of personal information we process, we will notify affected parties, and where we act as a service provider or processor, the affected customer, without undue delay and consistent with applicable data breach notification law. Internally, our incident commander must issue at least a preliminary notification within 72 hours of confirming that an incident involves personal data. Notifications describe the incident, the categories of data involved and the measures taken, to the extent then known.
In the three years to 6 August 2026, SFN AI has not experienced a personal data breach that it notified, or was required to notify, to a regulator or to a customer.
Over the same period we have not received a complaint or regulatory correspondence about our processing of personal data.
Our production database runs automated backups with 14 day retention and point-in-time recovery. Backup storage inherits the same AES-256 encryption at rest as the database itself. Message queues retain undelivered messages in a dead letter queue for 14 days rather than dropping them, and the queue infrastructure is redeployable from templates.
Personal data captured in routine backups is purged as those backups age out of the retention window. There is no separate manual purge step once the primary records have been deleted.
Any laptop that can reach production credentials, our source repository or systems holding personal data is covered by a written Endpoint Protection Policy. On every such device today:
We do not yet run a dedicated managed endpoint detection product. Selecting and deploying one is a committed item in the same policy. Any malware detection or compromise on a device with production access triggers the incident response process immediately, including rotation of every credential that device held.
SFN AI is a small engineering organization. Access to customer and creator data is limited to the people who need it to operate and support the service, and that limit is implemented in the access policies described in Section 5 rather than left to good intentions.
Any contractor or consultant granted access to our systems is bound by a written confidentiality agreement and is scoped to least-privilege, read-only access before that access is issued.
Content Rewards involves the most sensitive information SFN AI touches. This section says where it goes and who holds it.
Pay-in. A seller purchases a campaign service from SFN AI and pays SFN AI for it. SFN AI is the merchant of record, and Stripe, Inc. processes those payments. Card details are entered into and handled by Stripe. Stripe's security controls and certifications are Stripe's, and we do not represent them as our own.
Payout, identity and tax. SFN AI commissions content from creators in its own name and pays each reward from its own funds, as its own obligation. A seller never pays a creator. Trolley, or another financial partner we designate, executes those payments. Before a creator's first payout, identity verification and tax documentation, including a valid IRS Form W-9, are collected by Trolley through an embedded onboarding flow. Age is verified as part of that process.
What we do not store. Identity document images, full taxpayer identification numbers and full bank account numbers are collected and held by Trolley in its own secure frame. SFN AI does not store any of them. Our product analytics recordings do not capture those screens, because they are served by Trolley from a separate origin.
SFN AI is a technology platform, marketing services provider and content production company. SFN AI is not a bank, money transmitter or financial institution, and does not offer deposit, checking, savings, stored value, prepaid or money transfer accounts or services.
Our application and its data stores run in AWS Frankfurt, Germany. The AI model inference we run to generate angles, content ideas and scoring also runs in Frankfurt. Our product analytics provider processes in the European Union. Our marketing website is hosted on Netlify's distributed edge network.
Administrative access originates from the personal devices of our founding team, including while travelling. Every one of those access points is individually listed on the allowlist described in Section 4, and all administrative access runs over TLS. As a matter of policy, personal data is not persisted to local devices.
Per-vendor detail, including exactly what each one receives and where it processes, is on our Sub-processors page.
We have a written Data Retention and Deletion Procedure with an owner, a trigger and a runbook.
Deletion and access requests are fulfilled manually by our engineering team today rather than through a self-service flow. How to make one is set out in our Privacy Policy.
We use third-party service providers to operate SFN AI. Each one receives only the information it needs to perform its function, and we require appropriate security and confidentiality protections by contract.
Any new provider that would receive seller or creator personal data has to be reviewed against our Information Security Policy before it is integrated.
This page points at the list. It does not keep a second one. The current providers, what each receives and where each processes are set out on our Sub-processors page, which is dated so you can see when it was last reviewed.
SFN AI does not hold a SOC 2 Type II report and does not hold an ISO/IEC 27001 certification. Nothing on this page should be read as claiming otherwise.
Our cloud infrastructure providers hold their own certifications. Those are the providers' and not ours.
We welcome reports from security researchers and from the wider community. If you believe you have found a vulnerability or a security issue in SFN AI, report it to us privately so we can investigate and fix it before any details are made public.
We appreciate good-faith research and will work with you to confirm and resolve valid reports.
No method of transmission over the internet or of electronic storage is completely secure. We do not warrant that the SFN AI platform and services, or any data, will be free from unauthorized access. We work to protect your information and we improve our practices as threats and technology change, but we cannot guarantee absolute security.
We collect the information in this form to respond to you and to follow up about SFN AI, and we keep it for up to 12 months. We share limited advertising identifiers with advertising partners, which you can opt out of using in the footer. Full detail is in our Privacy Policy.