Trust
Security
A short, honest summary of how we protect your account and what to do if you spot a problem.
What we do
- HTTPS everywhere. Real Let's Encrypt certs at the load balancer; Cloudflare Full (Strict) mode.
- Bcrypt password hashing. We never store plain-text passwords.
- JWT sessions in HttpOnly cookies, scoped to our domain.
- Webhook signature verification on all payment events from Dodo.
- Rate limiting on login, signup, and password-reset endpoints.
- Regular dependency updates and tight environment isolation between test and production.
- We don't store payment card details — those go directly to Dodo Payments.
Reporting a vulnerability
If you find a security issue, please email [email protected].
What to include:
- What you found (a short description plus steps to reproduce).
- What an attacker could do with it.
- Optional: a suggested fix.
We'll acknowledge within 2 business days and keep you posted while we investigate. Please give us a reasonable window to fix things before disclosing publicly. We won't pursue legal action against good-faith researchers.
Out of scope
The following are typically not eligible:
- Reports from automated scanners without a clear exploit.
- Missing security headers without a demonstrable impact.
- Social engineering of staff or users.
- Denial-of-service attacks.
Breach notification
In the unlikely event of a personal data breach, we'll notify the EU supervisory authority within 72 hours, India's Data Protection Board without delay, and any affected user as soon as we've assessed the impact.