Skip to content
Affective

Security posture · Research stage

Sensitive state needs stronger proof.

Affective is testing person-state research, not operating a public state API. Inferred emotional and longitudinal data would be unusually sensitive. The controls below are design requirements for a future service, not a certification or a statement that a production system already holds this data.

01

Before any transcript review

A design-partner discussion begins with data rights, permitted uses, retention, access, and handling terms. Do not send personal or confidential conversations to our email address before those terms are agreed. The current diary research tier has not cleared participant contact or real enrollment.

02

Planned service controls

Our security architecture calls for tenant isolation, encryption in transit and at rest, restricted access to state and crisis data, auditable access, controlled secrets, and incident response. Each control needs implementation evidence and review before a service claim. We do not currently claim SOC 2 certification, HIPAA readiness, or an available production API.

03

Report a concern

Send vulnerability reports, privacy questions, and other communications to founder@affective-llc.site. Include the affected page or system and enough detail to reproduce the issue, but do not include sensitive third-party data in the first email.

Updated October 11, 2026. Product security requirements are described in Affective Docs; implementation and audit status must be verified separately before procurement or deployment.