Infrastructure & Safety

Platform Security

Last Updated: September 2026 • Standards for BulletType

1. Our Security Philosophy

At BulletType, operated by UMAR TECH, we take the confidentiality and integrity of our users seriously. Our platform is built from the ground up to minimize data collection: we only collect the minimum information required to deliver high-performance touch typing lessons and maintain community leaderboards.

2. Encryption & Data Transmission

TLS 1.3 / HTTPS Encryption

All communications between your web browser and our edge servers are encrypted in transit using industry-standard TLS 1.3 encryption certificates.

Secure Authentication

User passwords are never stored in plaintext. Authentication hashes use modern cryptographic algorithms with salted, adaptive key stretching.

3. Client-Side Safety & Device Isolation

The core typing test engine runs 100% locally within your browser tab. Your individual keypresses are evaluated in memory and are never transmitted across networks or logged on external servers as keylogger records. We only process finished test scores (WPM, Accuracy, Duration) when submitted to the leaderboard.

4. Responsible Disclosure Policy

We welcome responsible security disclosures from independent researchers and developers. If you discover a potential vulnerability, security flaw, or bug on BulletType, please report it directly to our engineering team before public disclosure.

Security Reporting Email: umar092939495@gmail.com

Subject Line: [Security Vulnerability] Summary of Issue

Please include reproducible steps, request logs, and proof-of-concept details. We acknowledge vulnerability submissions within 24 hours.