Built for hostile environments
Data encryption
- TLS 1.3 for all transit
- AES-256 at rest
- Signed session cookies (HMAC-SHA256)
- Strict Content-Security-Policy
Access controls
- Admin endpoints rate-limited (5 attempts / 15 min)
- CSRF tokens on all state changes
- HttpOnly + SameSite=Strict cookies
- Audit log for every privileged action
Bug bounty
Found a vulnerability? Email [email protected]. We credit every valid report publicly and ship a swag pack.
Data residency
All waitlist data resides in us-east-1 (AWS). No replication outside the US without notice.