Security
Last updated September 24, 2026
How we protect your account and your team's templates. Plain facts, no badges we haven't earned.
Infrastructure
- The app runs on Vercel and the database on Neon Postgres, both in the United States.
- All traffic uses HTTPS. Data is encrypted at rest by our infrastructure providers.
- The database keeps point-in-time backups managed by Neon.
Accounts and sign-in
- Passwords are hashed with bcrypt and a unique salt. We can't see them.
- Sessions use a random 256-bit token. The browser keeps it in a cookie that scripts can't read, and we store only a SHA-256 hash of it. Sessions expire after 30 days.
- Changing your password signs out every other device.
- Repeated wrong passwords lock that email out for 15 minutes, and floods of attempts from one network are blocked. Wrong emails and wrong passwords get the same answer, so attackers can't discover accounts.
- Deleting an account or a workspace asks for your password first.
Keeping workspaces apart
- Every page, action, and export checks who you are and which workspace you belong to.
- Every database query is scoped to your workspace, so one customer can't reach another's data.
- Admins control membership. Invite links can be replaced at any time, which disables the old one.
Template content
- Every template body is cleaned against a strict allowlist before it is saved, which blocks script injection.
- Fill-in values that members type stay in their browser and are never sent to us.
Your control over data
- Anyone can download their own data. Admins can export the whole workspace as JSON.
- Account and workspace deletion is self-serve and immediate. Backups roll off within 30 days.
What we don't have yet
We don't have a SOC 2 report or a formal penetration test yet. Enterprise customers can ask for our security questionnaire answers.
Reporting a vulnerability
Email [support email] with the details and steps to reproduce. Please give us reasonable time to fix the issue before sharing it, and don't access other people's data or disrupt the Service while testing. We won't take legal action against good-faith research that follows these rules.