Trust · Security

What's actually in place.

Transport & headers

All traffic is served over HTTPS (Let's Encrypt, auto-renewed). Responses carry a strict Content-Security-Policy, HSTS, and X-Frame-Options.

Access control

Sessions use signed tokens; administrative endpoints require a separate elevated role and are behind additional access gates. API access uses bearer keys scoped to your account, revocable from the platform console.

Abuse controls

API traffic is rate-limited; uploads pass through type checks; user-published HTML runs in a sandboxed frame; a reporting endpoint exists on every community surface.

Reporting

Found something? See Contact. Please avoid automated scanning against production; ask and we will arrange a window.