Private by default
Finders never see your name, email, phone number or address. You only see what a finder chooses to share.
Security at Regimate
Regimate connects owners with strangers who've found their things. Doing that safely means keeping everyone's identity private by default, stopping abuse before it lands, and being honest about how it all works.

Finders never see your name, email, phone number or address. You only see what a finder chooses to share.
Every uploaded image is re-encoded, which strips EXIF, GPS and other hidden metadata before it's stored.
Private files and finder conversations are reached only through HMAC-signed links that expire.
The Finder API logs a SHA-256 hash of each lookup, never the serial number or IMEI itself.
Account security
Sign-in is handled by a hardened authentication layer with origin and CSRF checks switched on, strict rate limits and sessions you can revoke instantly.
Every account has to verify its email address before it can sign in. Sign in with a password, a one-time emailed code, Google or Apple.
Emailed sign-in codes are six digits, stored hashed, expire after 10 minutes and allow five attempts. Requests are rate limited.
Passwords must be 8 to 128 characters and are stored only as salted, slow hashes. We can never see them.
See every signed-in device and revoke any of them from Settings. Revoking takes effect immediately, and a password reset signs out everywhere.
The iPhone and Android app keeps its session token in the device's secure keychain or keystore, never in plain storage.
Web sessions use HttpOnly, Secure, SameSite cookies and only trusted origins may send credentials.
Privacy engineering
The whole recovery flow is designed so that an owner and a finder can talk, arrange a handover and say thank you without either side learning who the other is.
Abuse prevention
An open messaging channel attracts bad actors. These controls are built into the platform, not bolted on.
Messages, item descriptions, thank-you notes and uploaded photos are checked by an AI moderation model. Anything doubtful is flagged for our team.
Anyone in a conversation can report it. Reports go to a moderation queue that our team aims to handle within 24 hours.
Owners can block a sender instantly. We can suspend messaging and temporarily ban the IP address behind repeated abuse.
Sign-in, messaging, uploads, finder contact and the API all have their own limits, backed by Redis.
A serial number or IMEI can only belong to one item in the whole registry, so a thief can't register your property before you do.
Alerts are rate limited per item and per asset, so nobody can flood your phone or inbox with notifications.
Encryption and hashing
| What | How it's protected |
|---|---|
| Traffic | TLS on every connection, with HTTP Strict Transport Security (one year, all subdomains). |
| Passwords | Salted, slow password hashing provided by our authentication framework. |
| Emergency PIN, security answers and passphrases | bcrypt (cost 12 for the PIN). Compared in constant time. |
| API keys | Shown once, then stored only as a bcrypt hash. Keys can expire and be revoked. |
| Sign-in and emergency codes | Stored hashed, expire in 10 or 15 minutes, with attempt limits and lockouts. |
| Property access notes | Encrypted in the application with AES-256-GCM, with key rotation. |
| Private files and conversation links | HMAC-signed URLs that expire (one hour by default). |
| Finder API lookups | Only a SHA-256 hash of the query is logged. |
| Database and file storage | Encrypted at rest by our infrastructure providers. |

Emergency Access
If your phone is lost with everything on it, Emergency Access lets you, or up to three people you trust, mark items lost and answer finders from any browser.
Infrastructure
The API runs in its own non-root container on a private network. Only the web gateway is exposed to the internet.
Managed Postgres for the registry, a private object store for files and Redis for rate limits and lockout counters.
HSTS, nosniff, a strict referrer policy, a locked-down permissions policy and framing protection on every response.
Every request body is validated against a schema and capped at 1 MB. Uploads are checked by their real file signature, not their name.
Images are capped at 2,560 px and 100 megapixels to stop decompression bombs, and uploads are limited to 10 MB.
Structured logs automatically redact authorisation headers, cookies, tokens and signed URL parameters.
Data retention
A retention job runs every day and removes data once it's no longer needed. When you delete your account, your items, conversations and files go with it.
| Data | Kept for |
|---|---|
| Sign-in codes | 10 minutes |
| Emergency access codes | 15 minutes |
| Finder conversation links | 30 days, renewed while in use |
| Signed-in sessions | 30 days |
| Private uploads never attached to anything | 7 days |
| Finder email addresses | Cleared 90 days after the last message |
| Finder and reporter IP addresses and shared locations | 12 months |
| Moderation and Emergency Access logs | 12 months |
| Finder conversations and property incidents, including photos | 2 years |
Full details are in our Privacy policy.
We welcome reports from security researchers and won't take legal action against good-faith research that follows our policy. Email security@regimate.app with the details and we'll get back to you.
Free for personal use
Register your first item in under a minute. When it matters, whoever finds it can reach you, and you stay private.