Security & Trust

How we protect your credit data.

Effective July 2026 · Last reviewed July 2026

This page is maintained by Fix My Reports to answer common security and privacy questions about our platform. It describes controls that are currently enabled in production. It is not an independent certification or audit report.

Where your data lives

The Fix My Reports portal runs on managed cloud infrastructure. Application traffic is served over HTTPS/TLS end-to-end — the browser never talks to our servers in the clear. Our production database and file storage are operated by our managed backend provider inside their hardened environments; we do not host physical database servers ourselves.

Data is stored in the United States. We do not sell your personal information. See our Privacy Policy for the full data-handling detail.

Encryption in transit and at rest
  • In transit: every request between your browser, our app, and our backend is encrypted with TLS 1.2 or higher, and the site is served exclusively over HTTPS.
  • At rest: the managed database and object storage where your report data and dispute letters live encrypt stored data at rest at the disk level by default.
What we don't collect

Fix My Reports does not collect or store your full Social Security number, your date of birth, or copies of your government ID, SSN card, or proof-of-address documents. Because every dispute letter is reviewed, signed, and physically mailed by you, we generate letters with blank fill-in-yourself lines for SSN and DOB and rely on you to attach the required ID copies to the envelope before sending. Nothing sensitive is ever written to our database because nothing sensitive is ever uploaded to us in the first place.

The only personal information we hold is what's needed to draft letters and communicate with you: your name, mailing address, phone, email, and the credit-report data pulled through our reporting partner.

Access controls
  • Row-level isolation: every table that holds customer data enforces database-level row security. Your account can only read and write rows tied to your own user, and that rule is applied by the database itself — not just by application code.
  • Role separation: customer accounts, affiliate accounts, and internal staff each get a distinct role. The role a user holds is stored in a dedicated table and checked by a security-definer function, so it can't be spoofed by a modified client.
  • Least-privilege staff access: only a small number of Fix My Reports operators can access the underlying admin tooling, and even then only for support, billing, or fraud-review reasons. Admin actions are taken through the same authenticated APIs, not by opening raw database tables in a UI.
  • No password reuse for third parties: we do not ask for or store your SmartCredit password, your bank login, or any other third-party credential. We pull your report through a partner integration that uses its own token, not your password.
Retention and deletion
  • While your account is active: we keep your profile, report snapshots, and dispute letters so you can review the full history of each dispute round.
  • Letter body cleanup: full generated letter text for old, already-sent rounds is periodically purged from long-term storage while the summary metadata (what was disputed, when, and the outcome) is kept.
  • When you cancel: we stop pulling new reports immediately and stop billing. You can request deletion of your account and associated documents at any time by emailing info@fixmyreports.com — see the Privacy Policy for the full data-rights process.
Payments

Card payments are processed through Authorize.Net via our payment partner. Your full card number never touches our servers — the browser tokenizes the card directly with the processor, and we only store a processor-side customer/payment profile identifier and the last four digits of the card so you can recognize it. That means a compromise of our database would not expose usable card numbers.

Who sees your data
  • You, when signed into your account.
  • A small number of Fix My Reports operators, for support, billing questions, and fraud review only.
  • Service providers we rely on to run the product — our managed backend host, our email delivery provider, our payment processor, and our credit-report data partner — each under their own security terms. We list these subprocessors in our Privacy Policy.
  • Never: data brokers, advertisers, or marketing lists. We do not sell your personal information.
Reporting a security concern

If you believe you've found a security issue — a way to access another user's data, a bypass of authentication, a leaked credential, or anything similar — please email info@fixmyreports.com with the subject line Security report. Include steps to reproduce and any relevant URLs or account IDs.

We ask that you avoid running automated scans against production, avoid accessing accounts other than your own, and give us a reasonable window to respond before publishing details.

Shared responsibility

The strongest single thing you can do to protect your account is to use a unique password for Fix My Reports and to sign out of shared devices. We handle transport, storage, access controls, and payment tokenization; you control who has your login. If you ever suspect your account has been used without your permission, change your password and email us right away.

See also our Privacy Policy and Terms of Use.