Infrastructure & Safety
Platform Security
Last Updated: September 2026 • Standards for BulletType
1. Our Security Philosophy
At BulletType, operated by UMAR TECH, we take the confidentiality and integrity of our users seriously. Our platform is built from the ground up to minimize data collection: we only collect the minimum information required to deliver high-performance touch typing lessons and maintain community leaderboards.
2. Encryption & Data Transmission
All communications between your web browser and our edge servers are encrypted in transit using industry-standard TLS 1.3 encryption certificates.
User passwords are never stored in plaintext. Authentication hashes use modern cryptographic algorithms with salted, adaptive key stretching.
3. Client-Side Safety & Device Isolation
The core typing test engine runs 100% locally within your browser tab. Your individual keypresses are evaluated in memory and are never transmitted across networks or logged on external servers as keylogger records. We only process finished test scores (WPM, Accuracy, Duration) when submitted to the leaderboard.
4. Responsible Disclosure Policy
We welcome responsible security disclosures from independent researchers and developers. If you discover a potential vulnerability, security flaw, or bug on BulletType, please report it directly to our engineering team before public disclosure.
Security Reporting Email: umar092939495@gmail.com
Subject Line: [Security Vulnerability] Summary of Issue
Please include reproducible steps, request logs, and proof-of-concept details. We acknowledge vulnerability submissions within 24 hours.