Security
Last updated: 30 June 2026
We take the security of the Service and your data seriously. This page summarizes our practices and how to report a vulnerability.
Our practices
- All traffic is served over TLS (HTTPS).
- API keys are stored only as salted hashes, never in plaintext.
- Heavy and sensitive workloads run in isolated containers to limit blast radius, and we apply rate-limiting at the edge.
- We follow least-privilege access to production systems.
Reporting a vulnerability
If you believe you've found a security issue, please email [email protected] with details and steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and do not access or modify data that isn't yours while testing.
Scope
The Service's web app and public API are in scope. Denial-of-service testing, social engineering, and physical attacks are out of scope.
Contact
Questions about this policy? Email [email protected].
This page is provided for general information and convenience only and is not legal advice.