Secure authentication
Password hashing, email verification, password confirmation, rate limits, two-factor authentication, recovery codes, and supported passkeys protect account access.
Security
Factual controls for authentication, account access, provider authorization, and reproducible deployment.
Password hashing, email verification, password confirmation, rate limits, two-factor authentication, recovery codes, and supported passkeys protect account access.
Accepted account memberships and scoped roles separate owners, managers, members, and platform administration.
Cloudflare and Google authorization use state and PKCE. Stored access and refresh tokens use encrypted model casts and are not rendered back to customers.
Generated artifacts retain policy revision, renderer version, checksum, and frozen dataset provenance.
Hosted block telemetry excludes request bodies, query strings, cookies, authorization headers, full referrers, raw User-Agent strings, and persistent raw IP storage.
Generated origin rules and deployed provider rules do not depend on dashboard availability or optional telemetry to continue enforcing.
Use the configured security contact on the Contact page. If it is not configured, production launch remains blocked on that operational requirement.
Necessary storage runs and secures the service. Optional analytics and marketing are disabled unless chosen; no optional trackers are currently loaded.