Security
Last updated: August 7, 2026
This page is here so that somebody who finds a problem knows where to send it, and so that anybody wondering how an account is protected can read it rather than ask.
How an account is protected
- Signing in is a six digit code sent to your address, or Google, Apple or Microsoft. Codes work once, expire in ten minutes, and burn after five wrong guesses.
- Passwords are optional and most accounts have none. Where one exists it is stored as a slow one-way hash, never as text.
- Every device that signs in is listed in Settings and can be revoked from any other device.
- Anything irreversible, such as deleting an account or erasing a device, needs a fresh code sent to your address. A stolen session is not enough.
- Traffic is HTTPS only, with strict transport security set at the edge.
- Payment card details never reach Buhata. Checkout happens on our payment provider’s own page.
Reporting a problem
Write to [email protected] with enough detail to reproduce it. Please do not open an issue in public before we have replied.
We will acknowledge within five working days and tell you what we intend to do. We do not pay a bounty, and we will say so early rather than let you spend a week hoping. What we will do is credit you when a fix ships, if you would like that.
Please do not run automated scanners against the service, access an account that is not yours, or degrade it for anybody else while testing. Acting in good faith and within that, we will not pursue you.
What we ask you to do
Keep the address on your account current, since it is how you get back in. Review your devices in Settings now and then and revoke the ones you no longer use.
Contact
Security reports and everything else: [email protected], with SECURITY in the subject so it is picked up first. Buhata LLC, Pensacola, FL 32534, United States.
