Trust · Security
What's actually in place.
Transport & headers
All traffic is served over HTTPS (Let's Encrypt, auto-renewed). Responses carry a strict Content-Security-Policy, HSTS, and X-Frame-Options.
Access control
Sessions use signed tokens; administrative endpoints require a separate elevated role and are behind additional access gates. API access uses bearer keys scoped to your account, revocable from the platform console.
Abuse controls
API traffic is rate-limited; uploads pass through type checks; user-published HTML runs in a sandboxed frame; a reporting endpoint exists on every community surface.
Reporting
Found something? See Contact. Please avoid automated scanning against production; ask and we will arrange a window.