Security overview
Current safeguards, their limits and how to report a concern.
Last updated September 22, 2026Current safeguards
The website uses HTTPS. Account workspaces use Supabase authentication and owner-scoped database access. Public release packaging includes an explicit asset list and excludes customer workspaces. Signing in and importing local data are separate actions.
Your part
Keep control of your email inbox, never share sign-in links or codes, and sign out on shared devices. Export work you need to retain. Local browser notes are accessible to someone using the same browser profile; local storage is not a password-protected document vault.
Limits
We do not claim SOC 2 or ISO certification, a completed independent penetration test, guaranteed uptime, zero risk or a contractual recovery time. The service is a preview. A final incident, retention and backup schedule is still needed for commercial agreements.
Report a concern
Email [email protected] with the affected URL, a description and non-sensitive reproduction steps. Do not send credentials, another person’s records or confidential attachments. This page does not authorize access to other accounts, disruptive testing or a bug-bounty payment.