Skip to content

Control

Browser sessions

Server-set secure cookies with CSRF protection. Browser sessions and API keys are never stored in localStorage.

Control

Authentication

Password-manager-compatible fields, rate limits, generic recovery responses, email verification, and TOTP MFA support.

Control

Operations

Least-privilege access, immutable audit events, encrypted secrets outside images and client bundles, and controlled environment promotion.

Control

Reporting

Report suspected vulnerabilities through the security contact listed in SECURITY.md. Avoid automated scanners against production routes.

Session changes stay visible.

Sign-in, MFA changes, session revocation, and account security notices link back to session management so you can review active access.