Pre-Launch Security Statement · Protecting Truth and Trust · Return to DemoCry →
Legal Document · Platform Security

Security Statement

Everything we do to protect you, the vote, the mission, and the truth itself from those who would seek to compromise any of it.

Version 1.0 · Pre-Launch
Effective: 26 June 2026
Contents
  1. Our Threat Model
  2. Security Principles
  3. Data Encryption
  4. Authentication & Access
  5. Video Verification Security
  6. Blockchain Integrity
  7. Infrastructure Security
  8. Payment Security
  9. Operational Security
  10. Vulnerability Management
  11. Incident Response
  12. Breach Notification
  13. Responsible Disclosure Program
  14. Your Role in Security
  15. Nation-State & Advanced Threats
  16. Physical Security
  17. Audits & Certifications
  18. Contact Security Team

Security is not an add-on at DemoCry. It is a foundational principle woven into every technical, operational, and policy decision we make.

This statement explains how we protect your data, your identity, your vote, and the integrity of the Platform itself against the full range of threats we anticipate — from ordinary cybercrime to sophisticated state-level adversaries.

01Our Threat Model

Because DemoCry challenges established interests, we operate under a threat model that anticipates:

Our security architecture is designed to remain effective even when facing well-resourced, sophisticated adversaries — because we believe that eventually, we will.

02Security Principles

Everything we build follows these principles:

Minimum Data

Collect only what is essential. What we don't hold can't be stolen.

Encryption Always

Data encrypted in transit and at rest. No exceptions.

Zero Trust

Every request verified. No implicit trust based on network location.

Defense In Depth

Multiple independent security layers. No single point of failure.

Least Privilege

Access limited to the minimum needed for each role or system.

Transparency

Open about our architecture. Security through resilience, not obscurity.

Immutability

Critical records (votes, allocations) permanent and tamper-evident.

Rapid Response

Incidents contained fast. Users notified promptly.

03Data Encryption

Data Type Encryption Standard
Data in transit TLS 1.3 (all connections) TLS 1.3 · AEAD ciphers
Data at rest (database) AES-256 encryption AES-256-GCM
Passwords One-way cryptographic hash (never stored in plain text) bcrypt · argon2id
Video verification files End-to-end encrypted during transit, encrypted at rest, deleted within 72 hours AES-256 · deleted
Backups Fully encrypted with separately managed keys AES-256 · KMS
Session tokens Cryptographically signed, short-lived, HttpOnly + Secure JWT · rotated

Encryption keys are managed through a dedicated key management system with strict access controls, key rotation, and independent audit trails.

04Authentication & Access

User Authentication

Internal Access Controls

05Video Verification Security

Video verification is a special-category data flow requiring additional protection.

Data Flow Protection

  1. Video captured client-side in the user's browser (never leaves their device unencrypted)
  2. Encrypted with per-session key before transmission
  3. Transmitted via TLS 1.3 to our AI verification service
  4. Verification result computed and cryptographically signed
  5. Only the signed verification result is retained; the video file is deleted
  6. Deletion is confirmed and logged (audit trail)

What We Never Do

06Blockchain Integrity

Why Blockchain

Votes and financial allocations are recorded on the Stellar blockchain because blockchain provides three properties that traditional databases cannot:

How We Protect Blockchain Operations

07Infrastructure Security

Hosting

DemoCry infrastructure is hosted with reputable cloud providers who maintain SOC 2 Type II and ISO 27001 certifications. All hosting agreements include strong data protection clauses.

Network Security

Application Security

08Payment Security

We do not store full payment card details or bank credentials on our systems. All payment processing is handled by PCI-DSS Level 1 certified payment processors (Stripe, M-Pesa, and equivalent).

What we retain internally:

Refund and dispute processes go through the original payment processor, which handles the sensitive financial data throughout.

09Operational Security

Team Security

Third-Party Risk

10Vulnerability Management

11Incident Response

We maintain a documented Incident Response Plan covering:

The Incident Response Team includes technical, legal, and communications leads to ensure rapid and coordinated response.

12Breach Notification

If a security incident affects your personal data:

Important We will never ask for your password, 2FA codes, or other credentials via email, phone, or messaging. If someone claims to be from DemoCry and asks for these, it is fraud. Report immediately to security@democry.world.

13Responsible Disclosure Program

We welcome security research and responsible disclosure of vulnerabilities.

Security Researcher Program

If you discover a vulnerability in DemoCry, please:

1. Report privately to security@democry.world
2. Encrypt sensitive details using our PGP key (available on request)
3. Give us reasonable time to remediate before public disclosure
4. Do not access user data beyond what is necessary to demonstrate the issue
5. Do not perform testing that would degrade service for other users

In return, we:

· Acknowledge your report within 48 hours
· Keep you informed of remediation progress
· Publicly credit you (with your permission) once resolved
· Offer bug bounties as budget permits (details on request)
· Never pursue legal action against good-faith security researchers

14Your Role in Security

Even the best platform security can be undermined by user-side compromise. To protect your account:

15Nation-State & Advanced Threats

DemoCry publishes political and social content, and hosts vote data of potential interest to state-level actors. We architect our systems accordingly:

What We Do

What We Cannot Do

No security system is invulnerable against a determined nation-state adversary with unlimited resources. What we can guarantee is that:

16Physical Security

Physical security matters when the platform is operated by real humans in real places.

Team Safety

Infrastructure Physical Security

Cloud infrastructure providers we use maintain physical security including:

17Audits & Certifications

As DemoCry grows, we will pursue and maintain:

Audit results and any material findings will be summarized in public transparency reports.

Current Status: DemoCry is in pre-launch phase. Full formal audit and certification programs will be implemented as operational scale justifies. Every security control listed in this statement is either currently implemented or on the immediate roadmap for pre-launch completion.

18Contact Security Team

Security Contacts

General Security Inquiries: security@democry.world

Vulnerability Reports: security@democry.world (PGP key on request)

Suspected Account Compromise: security@democry.world

Phishing Reports: security@democry.world

Emergency Incidents: Include "URGENT" in subject line — we monitor and prioritize accordingly

We aim to acknowledge security reports within 48 hours.
Critical vulnerabilities acknowledged within 24 hours.

Security is not a feature.
It is the foundation.
Without it, everything else falls.