Security
Effective October 1, 2026. The measures we use to protect personal data (GDPR Art. 32) and how to report a problem.
How we protect your data
- Passwords are stored only as salted one-way hashes. Sign-in is rate-limited per address and per account, and unknown emails cost the same effort as wrong passwords (no account-existence timing leak).
- Two-factor authentication (authenticator app) is available; its secret is encrypted at rest (AES-256-GCM), recovery codes are stored only as keyed hashes and each code works once.
- Sessions use HttpOnly, SameSite cookies; refresh tokens rotate and a replayed old token revokes the session. You can see and sign out your devices in Settings.
- Encryption in transit (HTTPS with HSTS) and at rest for secrets such as GitHub tokens and integration credentials.
- Payments are handled by PCI-DSS-certified processors; we never see card numbers. Wallet balances change only through single guarded database operations, every movement is recorded, and payments are verified with the processor on our servers before any money is credited.
- Access control: customers only ever reach their own data; administrator accounts are created only by a super admin, every sensitive administrator action needs a written reason and is written to an audit log, and super-admin-only functions are re-verified against the database on every call.
- Web protections: Content-Security-Policy, clickjacking protection, CSRF protection on every state-changing request, request-size limits, and protection against server-side request forgery on outbound links.
- Data minimisation and deletion: one-time codes, expired sessions, old notifications and unpaid uploads are removed automatically; deleted accounts are recoverable for a fixed window and then erased (see the Privacy Policy).
Breaches
We keep an incident-response procedure. If a personal-data breach is likely to put people’s rights at risk we notify the competent supervisory authority within 72 hours of becoming aware and tell affected people without undue delay; where US state breach-notification laws apply we follow their deadlines and content rules.
Report a vulnerability
Email [SECURITY EMAIL] with the details. Please give us reasonable time to fix an issue before disclosing it, do not access other people’s data, and do not disrupt the service. We will acknowledge your report and keep you informed.
No system is perfectly secure; these are the measures we operate, not a guarantee.