← Back to IT Book

Terms of Service & Disclosure Agreement

Last updated: June 2026

1. Service Description

IT Book ("portalserver.net") is an IT operations platform that provides asset tracking, credential management, access control, vendor management, and audit logging for organizations. The service is provided by Hudson Signals LLC.

2. Credential Encryption & Security Disclosure

IT Book uses envelope encryption to protect credentials stored in the vault:

  • Key derivation: PBKDF2-SHA256 with 100,000 iterations derives an encryption key from your password.
  • Encryption: Fernet symmetric encryption (AES-128-CBC with HMAC-SHA256 for authentication).
  • Zero-knowledge architecture: Each user's copy of the tenant encryption key is encrypted with their own password. We store only ciphertext and cannot decrypt your credentials without your password.

Limitations & Risks You Accept

  • AES-128 vs AES-256: Fernet uses AES-128-CBC, not AES-256. While AES-128 remains secure against known attacks as of 2026, it provides a lower security margin than AES-256. For most threat models this is adequate, but organizations with nation-state-level adversaries should evaluate independently.
  • Password dependency: The security of your vault depends entirely on your password strength. A weak password makes the encryption trivially breakable regardless of the algorithm.
  • No password recovery: If you lose your password and have no other executive user who can re-grant vault access, your encrypted credentials are permanently inaccessible. We cannot recover them.
  • In-memory exposure: Decrypted credentials exist in server memory briefly when accessed. While we clear them after use, memory-based attacks on the server could theoretically expose credentials during this window.
  • No hardware security module (HSM): Encryption keys are derived in software, not protected by hardware. This is standard for SaaS but less secure than HSM-backed solutions.
  • Invite code as key material: When you create an invite code, the tenant encryption key is re-encrypted with that code. Anyone with the invite code can derive vault access. Treat invite codes as sensitive.

3. Data Storage & Responsibility

  • Your data is stored in AWS-hosted PostgreSQL databases.
  • We do not access, read, or share your stored credentials.
  • You are responsible for maintaining backups of credentials stored outside IT Book.
  • Account deletion permanently removes all data. This cannot be undone.

4. Use at Your Own Risk

IT Book is provided "as is" without warranty of any kind. By creating an account, you acknowledge that:

  • You understand the encryption limitations described above.
  • You accept responsibility for password strength and credential management.
  • You will not hold Hudson Signals LLC liable for data loss or unauthorized access resulting from weak passwords, compromised invite codes, or limitations of the encryption implementation.
  • You agree to use the service in compliance with applicable laws.

5. Credential Accuracy & Sharing

  • We do not guarantee the accuracy, validity, or correctness of any passwords, credentials, or information stored in the vault. Users are solely responsible for verifying that credentials they store are correct and current.
  • When granting or sharing credential access with other users, you are responsible for verifying recipient email addresses. We are not liable for credentials shared with unintended recipients due to incorrect email entry.
  • Access grants are your responsibility. Once you grant access to a user, they can view and use those credentials. Verify recipient identity before granting.

6. Password Strength & Security Responsibility

  • We enforce minimum password complexity requirements (8+ characters, uppercase, lowercase, number, special character). However, meeting minimum requirements does not guarantee security.
  • You are solely responsible for choosing a sufficiently strong password for your threat model. We are not liable for unauthorized access resulting from weak, reused, or compromised passwords.
  • We strongly recommend using unique passwords not used on any other service.

7. Breach & Liability Limitation

  • We are not responsible for any security breach that occurs due to: weak passwords, password reuse, compromised devices, social engineering, sharing credentials with unauthorized parties, or any user action that undermines the encryption model.
  • In no event shall Hudson Signals LLC be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business opportunities.
  • Maximum aggregate liability shall not exceed the amount paid by you in the 12 months preceding the claim.

8. Privacy

We collect and store:

  • Account information (email, name, company name)
  • Encrypted credential data (we cannot read it)
  • Audit logs of actions taken within your tenant
  • Standard web server logs (IP addresses, timestamps)

We do not:

  • Sell or share your data with third parties
  • Use tracking cookies or advertising pixels
  • Access your encrypted credentials

9. Account Termination

You may delete your account at any time from the Subscription page. All outstanding invoices must be paid before deletion. Upon deletion, all tenant data (users, assets, credentials, audit logs) is permanently and irreversibly removed.

10. Contact

For questions about these terms, email: support@hudsonsignals.com