Security
Precise about what protects you.
We list each control with its actual status. Where a control is planned, we say so.
Transport security
AvailableHTTPS with HSTS, no-sniff, strict referrer policy, and restricted browser permissions.
Deny-by-default access
AvailableMember and administrative routes refuse access unless an authorized session is present. No identity provider is connected yet, so all such routes currently deny.
Input validation and abuse controls
AvailableApplications are validated server-side, sanitized, rate limited, and protected by a spam trap.
Structured audit events
In developmentSensitive actions emit redacted audit events. Durable, tamper-evident storage is planned.
Member authentication with MFA
PlannedInvitation-only sign-in with multi-factor authentication.
Encryption at rest
PlannedEncrypted storage for applications and member research once persistence is enabled.
Independent assessment
PlannedThird-party penetration testing before member access opens. We hold no security certifications today.
To report a vulnerability, please reach us through the contact page.