Skip to content

Security at Regimate

Built to protect people, not just data.

Regimate connects owners with strangers who've found their things. Doing that safely means keeping everyone's identity private by default, stopping abuse before it lands, and being honest about how it all works.

An abstract violet and cyan shield made of light over a dark grid

Private by default

Finders never see your name, email, phone number or address. You only see what a finder chooses to share.

Clean photos

Every uploaded image is re-encoded, which strips EXIF, GPS and other hidden metadata before it's stored.

Signed, expiring links

Private files and finder conversations are reached only through HMAC-signed links that expire.

Hashes, not serials

The Finder API logs a SHA-256 hash of each lookup, never the serial number or IMEI itself.

Account security

Your account, locked down.

Sign-in is handled by a hardened authentication layer with origin and CSRF checks switched on, strict rate limits and sessions you can revoke instantly.

Verified email first

Every account has to verify its email address before it can sign in. Sign in with a password, a one-time emailed code, Google or Apple.

Short-lived codes

Emailed sign-in codes are six digits, stored hashed, expire after 10 minutes and allow five attempts. Requests are rate limited.

Strong password storage

Passwords must be 8 to 128 characters and are stored only as salted, slow hashes. We can never see them.

Sessions you control

See every signed-in device and revoke any of them from Settings. Revoking takes effect immediately, and a password reset signs out everywhere.

Secure on mobile

The iPhone and Android app keeps its session token in the device's secure keychain or keystore, never in plain storage.

Hardened cookies

Web sessions use HttpOnly, Secure, SameSite cookies and only trusted origins may send credentials.

Privacy engineering

Strangers can help. They just can't find you.

The whole recovery flow is designed so that an owner and a finder can talk, arrange a handover and say thank you without either side learning who the other is.

Finders message you through an anonymous thread. Replies reach them through a private link or, if they ask, a confirmed email address.
Public positions are snapped to roughly a kilometre. A finder's exact location is only shared if they choose to, and only with you.
Photos are re-encoded on upload: EXIF, GPS, XMP, IPTC and colour profiles are removed, and HEIC is converted.
Proof-of-ownership files and finder photos are stored privately and served only through signed links that expire.
One-click unsubscribe on every finder email, backed by a suppression list that stores a hash of the address, not the address.
A finder sees
The item and its photo
Whether it's lost or stolen
Any reward you've offered
A form to message you
Never shown
Your name
Your email or phone
Your home address
Your exact location

Abuse prevention

Safety rails on every message.

An open messaging channel attracts bad actors. These controls are built into the platform, not bolted on.

AI moderation

Messages, item descriptions, thank-you notes and uploaded photos are checked by an AI moderation model. Anything doubtful is flagged for our team.

Report and review

Anyone in a conversation can report it. Reports go to a moderation queue that our team aims to handle within 24 hours.

Blocks and bans

Owners can block a sender instantly. We can suspend messaging and temporarily ban the IP address behind repeated abuse.

Rate limits everywhere

Sign-in, messaging, uploads, finder contact and the API all have their own limits, backed by Redis.

No pre-registering stolen goods

A serial number or IMEI can only belong to one item in the whole registry, so a thief can't register your property before you do.

Throttled notifications

Alerts are rate limited per item and per asset, so nobody can flood your phone or inbox with notifications.

Encryption and hashing

The right tool for each secret.

What How it's protected
Traffic TLS on every connection, with HTTP Strict Transport Security (one year, all subdomains).
Passwords Salted, slow password hashing provided by our authentication framework.
Emergency PIN, security answers and passphrases bcrypt (cost 12 for the PIN). Compared in constant time.
API keys Shown once, then stored only as a bcrypt hash. Keys can expire and be revoked.
Sign-in and emergency codes Stored hashed, expire in 10 or 15 minutes, with attempt limits and lockouts.
Property access notes Encrypted in the application with AES-256-GCM, with key rotation.
Private files and conversation links HMAC-signed URLs that expire (one hour by default).
Finder API lookups Only a SHA-256 hash of the query is logged.
Database and file storage Encrypted at rest by our infrastructure providers.
A phone lock screen showing a Regimate emergency contact QR code

Emergency Access

Help when you're locked out. Walls when you're not.

If your phone is lost with everything on it, Emergency Access lets you, or up to three people you trust, mark items lost and answer finders from any browser.

Getting in needs your 6-digit PIN and an answer to one of your security questions, or a trusted contact's personal link plus their passphrase or an emailed code.
Three wrong PINs lock access for 30 minutes. Wrong answers, passphrases and codes have their own lockouts.
You're alerted by email and push every time the portal is used, and every time an attempt fails.
Portal sessions last two hours and can only list items, mark them lost and reply to finders.
Every access attempt is logged with its outcome and kept for 12 months.

Infrastructure

Defence in depth.

Isolated services

The API runs in its own non-root container on a private network. Only the web gateway is exposed to the internet.

Managed data stores

Managed Postgres for the registry, a private object store for files and Redis for rate limits and lockout counters.

Strict headers

HSTS, nosniff, a strict referrer policy, a locked-down permissions policy and framing protection on every response.

Validated input

Every request body is validated against a schema and capped at 1 MB. Uploads are checked by their real file signature, not their name.

Safe image processing

Images are capped at 2,560 px and 100 megapixels to stop decompression bombs, and uploads are limited to 10 MB.

Redacted logs

Structured logs automatically redact authorisation headers, cookies, tokens and signed URL parameters.

Data retention

We keep less, for less time.

A retention job runs every day and removes data once it's no longer needed. When you delete your account, your items, conversations and files go with it.

Data Kept for
Sign-in codes 10 minutes
Emergency access codes 15 minutes
Finder conversation links 30 days, renewed while in use
Signed-in sessions 30 days
Private uploads never attached to anything 7 days
Finder email addresses Cleared 90 days after the last message
Finder and reporter IP addresses and shared locations 12 months
Moderation and Emergency Access logs 12 months
Finder conversations and property incidents, including photos 2 years

Full details are in our Privacy policy.

Found a vulnerability? Tell us first.

We welcome reports from security researchers and won't take legal action against good-faith research that follows our policy. Email security@regimate.app with the details and we'll get back to you.

Free for personal use

Lost things deserve a way home.

Register your first item in under a minute. When it matters, whoever finds it can reach you, and you stay private.