NetGalley Security Updates

2025 NetGalley Security Updates:

  • Individual user credentials created for NetGalley publisher accounts, enhancing security and offering better user management and transparency within client accounts.
  • Company Administrators and Imprint Managers have access to Imprint Hub, User Profile & Alerts, and Imprint Users List.
  • Major upgrade to NetGalley Reading Options, expanding our commitment to making books easily and securely accessible to NetGalley members, however they like to read!
  • Launched the NetGalley Reader, a new proprietary in-browser reader offering a quick and secure reading experience in a web browser with a single click. No downloads or software required!
  • As part of NetGalley’s ongoing security efforts, also made adjustments to the “Download” Reading Option, replacing the older Adobe DRM with a more secure option: Licensed Content Protection (LCP).
  • Introduced new "Send to Kobo" integrated reading option in partnership with Rakuten Kobo.

2024 NetGalley Security Updates:

  • Member accounts with no activity after 3 years are automatically deleted.
  • Recaptcha added to the NetGalley registration page to prevent spam signups.
  • Updated Privacy Policy and Terms of Use.

March 8, 2023:

  • Users are prevented from reusing their last 12 passwords.
  • Accounts are temporarily disabled if there are 6 failed login attempts.
  • Only the domain portion of users' email addresses are visible to publishers when they view members' requests and reviews.
  • Internal logging processes are updated to ensure users are only identified by ID number in internal logs.
  • Personal data that is no longer in use on the platform, such as birthdays, has been deleted.
  • Implemented additional backend security checks and alerts for NetGalley administrators to identify potential issues.

Jan. 8, 2021:

  • Re-secured testing sites and updated internal protocols to ensure security going forward.
  • Revised database backup procedure to prevent future data exposure.
  • Changed all legacy passwords that had access to any NetGalley systems or data.
  • Ensured and enhanced security of content on cloud database.
  • Ended all sessions for all users, and required users to change their passwords.
  • Changed our password security to use a new encryption algorithm that offers increased security.
  • Prevented users from reusing the same password.
  • Allowed members to create stronger passwords (up to 30 characters, including special characters).
  • Improved how we store social media access credentials for all members (Goodreads, Twitter, LinkedIn). This improvement automatically disconnected members’ social media accounts from NetGalley, which they may reconnect at any time.
Was this article helpful?
21 out of 31 found this helpful