Current architecture
Public surfaces are statically generated. Authentication is mediated by same-origin server functions, session tokens remain in Secure HttpOnly cookies, and organization-scoped data uses PostgreSQL Row Level Security and membership checks.
Claims boundary
This page is not a certification, penetration-test attestation, compliance guarantee, or customer-specific security review. Enterprise controls, recovery objectives, incident terms, and production-data scope require a signed agreement.
Responsible reporting
Begin a report through the Contact page with the subject Security report. Do not include exploit code, credentials, regulated data, or personal information in the initial message.