Legal
Security
As Counted is operated by Ryan James Spencer, a sole trader in Australia, trading as As Counted (“As Counted”, “we”, “us” or “our”).
Reporting a vulnerability
If you think you have found a security problem in As Counted, email security@ascounted.com. Please include:
- what you found and where (the URL, API route, CLI command or MCP tool);
- steps to reproduce it; and
- what an attacker could do with it.
We will acknowledge your report, keep you updated while we fix it, and let you know when it is fixed. Please give us a reasonable time to fix a problem before you tell anyone else about it.
While investigating, please use only your own accounts and organizations, do not access or change other people's data, and avoid anything that would degrade the service for others, such as denial-of-service or automated high-volume testing. If you act in good faith within these limits, we will not pursue legal action against you for your research.
We do not run a bug bounty and do not pay for reports. We are glad to thank you publicly if you would like.
How we protect accounts and data
- No passwords to steal. People sign in with Google. We do not store passwords, and there are no static API keys.
- Roles and scopes on every action. The web app, API, CLI and MCP server all run commands through the same path, which checks the user's role (owner, manager or staff) and, for CLI and AI clients, the permissions the user granted: read, plan (dry runs) or write.
- Clients you can see and revoke. AI agents and other clients connect with OAuth and a consent screen that names the client and what it asks for. Grants are per user and organization and can be revoked. The device sign-in flow is reserved for our own CLI.
- Encrypted integration grants. Access grants for connected services such as Airtable and Salesforce are encrypted with AES-256-GCM, bound to their organization and connection, and never returned by the API or written to logs.
- A record of every change. Every command is logged with who made it, through which client, its input and its outcome, and every stock movement points to the command that made it.
- Encrypted in transit. The website, app and API are served over HTTPS only.
- Separated organizations. Every record belongs to one organization, and every request is limited to organizations the user is a member of.
- No trackers. No advertising or analytics trackers, and telemetry in our sign-in library is turned off.
- Hosting. As Counted runs on Cloudflare. See our subprocessors.
Contact
Security reports: security@ascounted.com. Privacy questions: privacy@ascounted.com.