Security
Draft — CMS copy not published yetProcessing
Every job runs in an isolated worker process with no network access and a hard time limit. Inputs are checked by content, not extension, before processing.
Accounts
Passwords are hashed with Argon2id. Two-factor authentication (TOTP) with recovery codes is available in Security settings. API keys are stored as SHA-256 hashes and shown once.
Transport
TLS everywhere, HSTS, and strict security headers.
What we do not claim
We do not run antivirus on uploads and we hold no compliance certifications we have not earned. If a certification matters to you, ask before relying on it.
Reporting
Found a vulnerability? Contact support with details; we respond to every report.