Skip to main content

Effective July 19, 2026

Security

Green Room uses layered access, storage, upload, and operational controls intended to protect confidential production information.

Security practices

  • Project-scoped row-level authorization and private storage.
  • Short-lived, forced-download links for confidential documents.
  • Upload quarantine, server-side file-signature validation, malware scanning, file-size limits, and project quotas.
  • Encrypted HTTPS transport, hardened browser headers, and restricted third-party scripts.
  • Signed and idempotent billing webhooks, outbound-email rate limits, and security audit events.
  • Support for account MFA, plus documented backup, monitoring, dependency-review, and incident-response procedures.

No system is perfectly secure. Users should enable MFA, use unique passwords, limit project membership, and avoid storing information that is not needed.

Report a vulnerability

Email contact@biglettuceentertainment.com with the subject “Green Room security report.” Include the affected URL, impact, reproduction steps, and a safe way to contact you. Do not access other users’ data, perform denial-of-service testing, use automated high-volume scanning, or publicly disclose an unresolved issue.

We will acknowledge credible reports, investigate, and coordinate remediation and disclosure in good faith. This statement does not authorize actions that violate law or third-party rights.

Security incidents

If you believe your account or project was compromised, change your password, remove unfamiliar project members, preserve relevant details, and contact us promptly. We maintain procedures for containment, investigation, recovery, and legally required notification.