Skip to content
StayMission

SECURITY

Clear access. Private records. Honest security practices.

Implemented safeguards and the remaining limits of the current free pilot.

Authentication and sessions

Passwords are hashed using scrypt. Verification and reset links are expiring, single-use tokens. Sessions use Secure, HttpOnly, SameSite=Lax cookies, and mutations require a matching origin and CSRF token. Administration uses SSH keys rather than public password login.

Tenant separation

Each organization has a separate SQLite database. Server-side membership selects the database; clients cannot supply a filesystem path. The shared identity database contains accounts, memberships, consent records and service status.

Role and owner boundaries

Permissions are checked on the server. Owners are restricted to currently linked properties and approved content. Workers are scoped to assigned work. File downloads repeat authorization checks.

Infrastructure and recovery

Traffic is encrypted with HTTPS. The server firewall exposes only SSH, HTTP and HTTPS, automated blocking protects repeated login abuse, and Hetzner maintains rolling infrastructure backups. A successful restoration test and independent security assessment remain outstanding.

Files and audit history

Uploaded files are served through authenticated endpoints. Allowlisted types and storage limits are enforced. Operational events record actor, action and time. Malware scanning, application-level encryption at rest and external tamper-evident audit retention are not currently implemented; do not upload identity documents, payment-card data or special-category information.

Report a concern

Report suspected unauthorized access promptly to [email protected]. Do not include passwords, access codes or unnecessary personal information in the report.

ONE WORKSPACE. A CLEARER WORKING DAY.

Run your portfolio
from one place.

Start your workspace

14-day Starter trial · No card required