Legal // Security

Security Brief

Last updated: October 5, 2026

Short version: HTTPS everywhere, the waitlist key never reaches your browser, we collect the minimum fields the form needs, and vulnerabilities go to dev@ppussh.com.

1. Scope

This brief covers the Movens marketing site and the waitlist form. The product itself is pre-launch and will get its own security documentation before launch.

2. Data in transit

Every page and every waitlist submission travels over HTTPS. Form data is sent from your browser to our server as a server action, then forwarded to our waitlist provider — it is never written into URLs or client-side storage.

3. Credentials

The waitlist API key lives only on our server, in the environment. Your browser never sees it, and one visitor's submission cannot read another's. Server-side secrets are not committed to the repository.

4. What we don't collect

This site takes no payment details, runs no ad trackers, no analytics cookies, and no third-party pixels. There is no account system on the site, so there are no passwords to leak.

5. Minimization

The only personal data this site holds is what you type into the waitlist form: product URL or name, what winning looks like to you, optional audience channels, and your founder work email. Less data in, less data to lose.

6. Reporting a vulnerability

Found something off? Email dev@ppussh.com with the details and steps to reproduce it. We read every report, confirm receipt, and follow up with you directly. Please give us a reasonable window to fix it before disclosing publicly.

7. Changes

The date at the top shows when this brief last changed. As the product moves toward launch we will expand it with infrastructure, access-control, and subprocessor details.