Skip to content

Security

Where the service runs, how accounts are protected, and how to report a vulnerability.

Hosting

The servers and the database run at Contabo GmbH, European Union (Germany). Cloudflare sits in front of the site.

Encryption

HTTPS everywhere with HSTS. Passwords are stored as salted hashes (scrypt), never in plain text. Authenticator secrets and recovery codes are stored encrypted.

Backups

Nightly encrypted backups go to a separate storage provider. Deleted data leaves the backups within 3 weeks.

Your account

Two-factor authentication uses an authenticator app and 10 one-time recovery codes. "Trust this device" lasts 30 days. It protects password sign-ins. Signing in with Google uses your Google account's security, so turn on 2-Step Verification there.

Email alerts go out for every two-factor change and for sign-ins from a new browser.

Lost your phone and your codes: email [email protected] from your account's address and we send a link to turn two-factor authentication off.

Our access

Staff accounts sign in with a password and two-factor authentication only, and staff actions in our admin console are logged.

Reporting a vulnerability

Email [email protected]. We reply within a few working days.

Please give us time to fix before sharing details publicly, and don't access other people's data or degrade the service while testing.