SECURITY
Clear access. Private records. Honest security practices.
Implemented safeguards and the remaining limits of the current free pilot.
Authentication and sessions
Passwords are hashed using scrypt. Verification and reset links are expiring, single-use tokens. Sessions use Secure, HttpOnly, SameSite=Lax cookies, and mutations require a matching origin and CSRF token. Administration uses SSH keys rather than public password login.
Tenant separation
Each organization has a separate SQLite database. Server-side membership selects the database; clients cannot supply a filesystem path. The shared identity database contains accounts, memberships, consent records and service status.
Role and owner boundaries
Permissions are checked on the server. Owners are restricted to currently linked properties and approved content. Workers are scoped to assigned work. File downloads repeat authorization checks.
Infrastructure and recovery
Traffic is encrypted with HTTPS. The server firewall exposes only SSH, HTTP and HTTPS, automated blocking protects repeated login abuse, and Hetzner maintains rolling infrastructure backups. A successful restoration test and independent security assessment remain outstanding.
Files and audit history
Uploaded files are served through authenticated endpoints. Allowlisted types and storage limits are enforced. Operational events record actor, action and time. Malware scanning, application-level encryption at rest and external tamper-evident audit retention are not currently implemented; do not upload identity documents, payment-card data or special-category information.
Report a concern
Report suspected unauthorized access promptly to [email protected]. Do not include passwords, access codes or unnecessary personal information in the report.
Run your portfolio
from one place.
Start your workspace14-day Starter trial · No card required