Skip to main content

Security

Last updated 2 October 2026

Reporting a vulnerability

If you have found a security issue, please email [email protected] with enough detail to reproduce it. We will acknowledge within a few working days.

Please give us a reasonable chance to fix it before disclosing publicly. We will not pursue anyone who reports in good faith, stays within the scope below, and does not access or destroy other people data.

Out of scope: denial of service, social engineering of our staff, physical attacks, spam, and automated scanner output with no demonstrated impact.

How the platform is built

Processing

Most tools run entirely in your browser. This is a security property as much as a privacy one: data we never receive cannot be leaked from our infrastructure, however badly we might otherwise fail.

Transport

  • HTTPS everywhere, with HSTS and a preload directive in production
  • TLS 1.2 and 1.3 only
  • HTTP requests are redirected before any application code runs

Browser protections

  • A Content-Security-Policy with per-request nonces and no unsafe-inline for scripts
  • X-Content-Type-Options: nosniff and a restrictive Referrer-Policy
  • A Permissions-Policy that denies microphone, geolocation and payment outright
  • Cross-origin opener and resource policies set to same-origin

Uploads, where a tool needs them

  • Size limits enforced before anything is read
  • The declared file type is never trusted — the real type is detected server-side and the file signature checked
  • Files are stored outside the web root under a randomly generated name, so nothing uploaded is ever addressable or executable
  • Automatic deletion within 60 minutes, enforced by a scheduled job independent of whether the job succeeded

Application

  • Every database query uses prepared statements with bound parameters
  • All output is escaped at the point of rendering
  • CSRF tokens on every state-changing request, compared in constant time
  • Rate limiting on every server-side tool and API route
  • Passwords, tokens and payloads are stripped from logs before they are written
  • Raw IP addresses are never stored — only salted, daily-rotating hashes

What we do not claim

No system is perfectly secure. We have described above what we actually do, rather than making broad assurances we could not stand behind. If you find somewhere the description and the behaviour disagree, that is a bug and we want to hear about it.