Security Policy

Last Updated: June 28 2025

Our Commitment to Security

At EmbroideryConverter.com, we take the security of your data and our software seriously. This Security Policy outlines the measures we implement to protect your information and ensure the integrity of our services.

Software Security

Code Integrity

  • All software releases undergo rigorous security testing
  • Code signing certificates ensure software authenticity
  • Regular security audits and vulnerability assessments
  • Secure development practices and code review processes

Download Security

  • Official downloads are available only from EmbroideryConverter.com
  • File integrity checksums provided for verification
  • Secure download links with SSL encryption
  • Malware scanning of all distributed files

Update Security

  • Automatic update notifications for security patches
  • Encrypted update delivery channels
  • Digital signature verification for all updates
  • Rollback capability for problematic updates

Data Protection

Personal Information Security

  • SSL/TLS encryption for all data transmission
  • Secure data storage with industry-standard encryption
  • Regular security assessments of data handling practices
  • Limited access to personal data on a need-to-know basis

Payment Security

  • PCI DSS compliant payment processing
  • No storage of credit card information on our servers
  • Secure payment gateways with fraud protection
  • Encrypted transmission of all payment data

File Processing Security

  • Your embroidery files are processed entirely on your local computer
  • No embroidery files or usage data are transmitted to our servers
  • The software only connects to the internet once to validate Pro licenses via Gumroad API
  • No “calling home” or telemetry data collection
  • Conversion processes run in sandboxed environments
  • Temporary files are automatically cleaned up after processing

Website Security

Infrastructure Security

  • Regular security monitoring and threat detection
  • Automated backup systems with secure storage
  • DDoS protection and traffic filtering
  • Regular security updates and patch management

Access Control

  • Multi-factor authentication for administrative access
  • Regular access reviews and permission audits
  • Secure administrative interfaces
  • Logging and monitoring of all administrative activities

Incident Response

Security Monitoring

  • 24/7 automated monitoring of security events
  • Regular security log reviews and analysis
  • Proactive threat detection and response
  • Incident escalation procedures

Response Procedures

  • Immediate containment of security incidents
  • Forensic analysis to determine impact and cause
  • Prompt notification of affected users when appropriate
  • Coordination with law enforcement when necessary

Vulnerability Management

Disclosure Policy
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue:

  • Email: [security@embroideryconverter.com]
  • Subject: “Security Vulnerability Report”
  • Include: Detailed description, steps to reproduce, and impact assessment

Response Timeline

  • Acknowledgment within 24 hours
  • Initial assessment within 72 hours
  • Resolution timeline based on severity
  • Public disclosure coordination with reporter

User Security Recommendations

Software Safety

  • Download software only from official sources
  • Keep your operating system and antivirus software updated
  • Use reputable antivirus software
  • Regularly backup your embroidery files

Account Security

  • Use strong, unique passwords for your accounts
  • Enable two-factor authentication when available
  • Keep your contact information current
  • Report suspicious activity immediately

Safe Computing Practices

  • Be cautious when downloading embroidery files from unknown sources
  • Scan downloaded files with antivirus software
  • Keep your system updated with security patches
  • Use secure networks for software downloads and updates

Compliance and Standards

Industry Standards

  • SOC 2 Type II compliance for service organizations
  • ISO 27001 information security management
  • GDPR compliance for data protection
  • Regular compliance audits and assessments

Legal Compliance

  • Adherence to applicable data protection laws
  • Compliance with international privacy regulations
  • Regular legal reviews of security practices
  • Cooperation with regulatory authorities

Security Updates

Notification Methods

  • Critical security updates via email to registered users
  • Security bulletins posted on our website
  • In-application notifications for important updates
  • Social media announcements for widespread issues

Update Categories

  • Critical: Immediate action required, security risk present
  • Important: Recommended installation within 7 days
  • Moderate: Recommended installation within 30 days
  • Low: Install at your convenience

Contact Information

Security Team

General Security Questions

Policy Updates

This Security Policy may be updated periodically to reflect changes in our security practices or legal requirements. We will notify users of significant changes and post the updated policy on our website.