Security overview — draft
The architecture uses private State RPCs, least-privilege Workers, server-managed sessions, bounded untrusted-content processing, and closed-schema telemetry.
Draft: this page is not an approved legal notice, intake channel, or service commitment.
Account protections
Password hashing, one-time verification and recovery tokens, session rotation and revocation, CSRF and exact-Origin checks, Turnstile on selected abuse surfaces, and stronger Access plus passkey controls for administration.
Source containment
Only the ingestion Worker can fetch arbitrary public URLs. It has no database, email, AI, authentication, Corridora, or private-network credential bindings.
Reporting
A public security-report intake address and response policy are still awaiting operational approval. Do not send secrets or personal data through an unapproved channel.
