Trust
Security
Defense in depth for authentication, APIs, and sensitive outputs — plus how to report issues responsibly.
Security is ongoing; details may evolve as the platform matures.
The platform applies authentication controls, rate limiting, webhook verification where applicable, and scoped data-access boundaries so account data is isolated per user.
Sensitive outputs are protected in transit (TLS) and processed server-side under strict API policies. Client bundles do not embed secrets; server routes enforce authorization before returning user-specific content.
For responsible disclosure, contact support with reproducible steps, affected components, and impact assessment. Please allow reasonable time for triage before any public discussion.
Read our privacy policy for data handling, or return to home.