AdvisorCalc Security and Vulnerability Disclosure Policy
Effective Date: June 17, 2026
AdvisorCalc is committed to taking reasonable steps to protect its users, systems, and information.
This policy describes selected security practices currently used by AdvisorCalc and explains how security researchers may report suspected vulnerabilities.
AdvisorCalc is operated by Howard Jay Cranford. Security reports may be sent to admin@advisorcalc.com.
1. Scope and limitations
This policy applies to systems and services controlled by AdvisorCalc, including:
- advisorcalc.com;
- AdvisorCalc account and subscription functionality;
- AdvisorCalc application programming interfaces; and
- Server-based calculator services operated for AdvisorCalc.
Third-party systems operated by Clerk, Stripe, Vercel, Render, domain registrars, email providers, or other vendors are not directly controlled by AdvisorCalc.
Suspected vulnerabilities in a third-party service should ordinarily be reported to the applicable provider through that provider’s reporting process.
This public policy is informational. It does not create a contractual warranty, service-level commitment, certification, or guarantee of security.
2. Current security practices
AdvisorCalc currently uses measures including the following.
Encryption in transit
AdvisorCalc uses HTTPS to protect communications between users and the Service.
Communications between the AdvisorCalc website and the calculator application programming interface are also transmitted using HTTPS.
Authentication
User authentication is provided through Clerk.
AdvisorCalc does not intentionally receive or store users’ plain-text passwords.
Users are responsible for selecting strong, unique passwords and protecting access to their email accounts and AdvisorCalc credentials.
Administrative account protection
Administrative access to important services, including hosting, authentication, billing, domain, and business-email systems, is protected with multi-factor authentication.
Payment security
Payment processing is provided through Stripe.
AdvisorCalc does not directly store full payment-card numbers.
Data minimization
AdvisorCalc seeks to limit the personal information it collects.
Calculator inputs are transmitted to the server-based calculation service only to perform the requested calculation and return the result.
AdvisorCalc does not intentionally retain calculator inputs or outputs as account history.
Users should not enter Social Security numbers, account numbers, credentials, government identification numbers, protected health information, or other unnecessary sensitive information into calculators.
Infrastructure providers
AdvisorCalc uses established third-party infrastructure and service providers, including Vercel, Render, Clerk, Stripe, PostHog, Better Stack, and staged Sentry error monitoring when configured.
These providers maintain and secure the underlying services they supply, subject to their own security programs, agreements, and responsibilities.
Monitoring and diagnostics
AdvisorCalc uses uptime monitoring, limited analytics and performance measurement, and may use metadata-only error monitoring and tracing when configured.
AdvisorCalc does not intentionally send calculator inputs, calculator outputs, assumptions, account identifiers, payment identifiers, request bodies, response bodies, cookies, or authorization headers to monitoring tools.
Session replay and payload-rich logging are not enabled unless a later privacy and security review explicitly approves them.
Administrative access
Access to production and administrative systems is limited to persons who require access to operate and maintain the Service.
AdvisorCalc is currently operated as a small owner-managed service.
Updates and maintenance
AdvisorCalc may apply software updates, dependency updates, configuration changes, and other maintenance intended to address operational or security risks.
No representation is made that every vulnerability will be identified or corrected within a particular period.
3. Security limitations
No website, network, software product, or storage system can be guaranteed to be completely secure.
Despite reasonable safeguards, the Service may be affected by:
- Software vulnerabilities;
- Misconfiguration;
- Credential compromise;
- Malicious activity;
- Third-party incidents;
- Internet or infrastructure failures;
- Human error; or
- Previously unknown threats.
AdvisorCalc does not guarantee that unauthorized access, disclosure, alteration, loss, or destruction will never occur.
Users should promptly report suspected unauthorized account access and should not reuse an AdvisorCalc password on another service.
4. Reporting a vulnerability
Security researchers and users may report a suspected vulnerability by emailing:
- admin@advisorcalc.com
- Please use a subject line such as:
- Security Vulnerability Report – AdvisorCalc
- A useful report should include, where available:
- A description of the suspected vulnerability;
- The affected page, endpoint, or feature;
- Steps required to reproduce the issue;
- The potential security impact;
- Relevant screenshots or request details;
- Whether any user information may have been accessed;
- Your name or preferred identifier; and
- A secure method for contacting you.
Do not include unnecessary personal information or sensitive data belonging to another user.
5. Authorized good-faith research
AdvisorCalc supports good-faith security research conducted carefully and responsibly.
Research is considered good faith under this policy when the researcher:
- Tests only systems within the stated scope;
- Makes a genuine effort to avoid harm;
- Accesses only the minimum information necessary to demonstrate an issue;
- Stops testing immediately if personal information, confidential information, or another user’s account is encountered;
- Does not retain, copy, disclose, alter, or destroy user information;
- Does not disrupt the Service;
- Does not demand payment or threaten disclosure;
- Reports the suspected vulnerability promptly;
- Allows AdvisorCalc a reasonable opportunity to investigate and address the issue; and
- Complies with applicable law.
6. Prohibited testing
This policy does not authorize:
- Accessing, modifying, downloading, or deleting another user’s information;
- Attempting to obtain another user’s password or session;
- Social engineering, phishing, impersonation, or physical attacks;
- Testing employees, contractors, providers, or users;
- Denial-of-service or distributed denial-of-service testing;
- High-volume automated scanning likely to impair the Service;
- Spam, flooding, or resource-exhaustion attacks;
- Malware distribution;
- Destructive testing;
- Testing third-party systems not controlled by AdvisorCalc;
- Physical intrusion;
- Extortion or demands for payment;
- Public disclosure before AdvisorCalc has had a reasonable opportunity to investigate and respond; or
- Any activity that violates applicable law.
If testing may affect availability, data integrity, user privacy, or third-party systems, obtain written permission before proceeding.
7. Handling accidentally accessed information
If you unexpectedly encounter personal, confidential, financial, authentication, or other sensitive information:
Stop testing immediately.
Do not copy, download, retain, alter, or disclose the information.
Notify AdvisorCalc promptly.
Describe the information only to the minimum extent necessary.
Follow reasonable instructions concerning secure deletion of any inadvertently retained material.
8. Our response
After receiving a report, AdvisorCalc intends to:
- Acknowledge receipt when reasonably practicable;
- Review the reported issue;
- Request additional information when necessary;
- Evaluate potential impact;
- Work toward remediation where appropriate; and
- Communicate material developments when reasonably practicable.
Because AdvisorCalc is a small service, we do not promise a specific acknowledgment, investigation, remediation, or disclosure timeline.
Submission of a report does not guarantee that:
- The report will be accepted as a vulnerability;
- A change will be made;
- A public credit will be provided; or
- Compensation will be paid.
9. No bug bounty
AdvisorCalc does not currently operate a paid bug-bounty program.
Do not assume that a payment, reward, credit, or other compensation will be provided.
Any reward offered in a particular case is discretionary and does not establish an obligation for other reports.
10. Coordinated disclosure
Please do not publicly disclose a suspected vulnerability until AdvisorCalc has had a reasonable opportunity to investigate and, where appropriate, correct the issue.
Where possible, we will work in good faith with researchers concerning a reasonable disclosure timeline.
11. Safe-harbor intent
AdvisorCalc does not intend to pursue legal action against a researcher solely for good-faith security research that complies with this policy.
This statement does not authorize unlawful activity, does not bind third parties, and does not protect conduct that:
- Causes harm;
- Accesses another person’s information beyond what is minimally necessary;
- Disrupts the Service;
- Violates privacy;
- Involves extortion or coercion;
- Targets third-party systems; or
- Otherwise falls outside this policy.
If you are uncertain whether planned research is permitted, contact admin@advisorcalc.com before testing.
12. Security incidents
Users who believe their account has been accessed without authorization should:
- Change their password;
- Secure the email account associated with AdvisorCalc;
- End other active sessions where available; and
- Contact admin@advisorcalc.com.
If AdvisorCalc identifies a security incident affecting personal information, it will investigate and provide notices required by applicable law.
13. Policy updates
AdvisorCalc may update this policy as its systems, security practices, providers, and operations evolve.
The latest version will be posted on advisorcalc.com with an updated effective date.
14. Contact
Security questions and vulnerability reports may be sent to:
- AdvisorCalc
- Email: admin@advisorcalc.com
- Website: advisorcalc.com