Theme
Security

Your security is our priority

We take security seriously. Here is what we have implemented to protect your data and what is on our roadmap.

What We Have Built

These security features are live and protecting your account today.

Live

Secure Authentication

JWT-based authentication with access and refresh tokens. Your sessions are securely managed with automatic token refresh.

Live

OAuth 2.0 with PKCE

Sign in with Google or Microsoft using OAuth 2.0 with PKCE (Proof Key for Code Exchange) for maximum security against interception attacks.

Live

Magic Link Authentication

Passwordless login option via secure email links. No password to remember or steal.

Live

HTTPS Everywhere

All communications between your browser and our servers are encrypted using HTTPS/TLS.

Live

Secure Password Reset

Token-based password reset flow with expiring links to ensure only you can reset your password.

Live

XSS Protection

Built-in protection against cross-site scripting attacks with content sanitization.

Current Security Practices

How we protect your data every day.

  • All API endpoints secured with HTTPS
  • CSRF protection on OAuth flows
  • Automatic session invalidation on logout
  • Secure token storage practices
  • Input validation and sanitization
  • Regular security updates and patches

Questions or concerns?

Our team is here to help. Reach out for security questions or to report a vulnerability.