Security
How this software protects accounts and data, and how to report a vulnerability.
Last updated: · Teniam
Placeholder — confirm before publishing
Everything below describes what the code does. What it cannot describe is how you run it: your hosting, your backups, your access controls, your incident response. Confirm each claim against your own deployment before publishing this page, and add the parts only you can answer.
Accounts
Passwords are hashed with a memory-hard function and never stored, logged, or emailed in the clear. Sessions are signed cookies; the signing key is an environment variable that must be set before the application will pass its own readiness check.
Optional, per account: passkeys (WebAuthn), time-based two-factor codes, and a notification when a new device signs in.
Administrative access is a role on the account record in the database. It is never inferred from an email address, a list in source, or anything the browser sends, and every administrative route re-checks it on the server.
Data
Your data lives in your own Postgres database, reached over TLS. Nothing in this application sends catalogue or account data to the vendor of this software.
Payments
Card details never reach this application. Stripe handles them; a placement is granted only by a webhook whose signature has been verified against your own signing secret, and never by a browser returning from a payment page.
AI features
When enabled, conversation text and the public content of analysed URLs are sent to a model provider. When no credential is configured, the features are hidden and the endpoints refuse — nothing is sent.
Content fetched from third-party sites is treated as untrusted data rather than as instructions, and URL fetching is guarded against requests to private network addresses.
Actions that change data
The AI assistant cannot write anything without a signed, per-session approval of that exact action with those exact arguments. Without a signing secret the write tools are removed entirely rather than left unsigned.
Reporting a vulnerability
Your security contact address, your response time, and your disclosure policy.