Legal

Security without the theater

Managed auth, per-user isolation and server-side secrets. The practices, stated plainly.

Get started

Managed auth

Sign-in and sessions through a dedicated auth provider with GitHub OAuth.

Per-user isolation

Every database call checks ownership before reading or writing.

Server-side secrets

Provider keys never ship in client bundles or public variables.

Encrypted transport

Everything moves over HTTPS; database connections are encrypted.

Tracked errors

Client, server and worker errors flow into monitored tracking.

Responsible disclosure

Found something? Report it and we will respond within two business days.

Build on solid ground.

Get started