Security

Separate what is active from what remains gated.

The desktop web app and API are active. This ledger distinguishes implemented repository controls from operational reviews and mobile-release gates that still require external verification.

Control ledger

Status is part of the control.

Active now

01

Static website boundary

The public website loads no third-party scripts, analytics, or application cookies. Browser requests are limited to the Alex Folzi API endpoints allowed by the deployed content security policy.

Implemented control

02

Identity and access

Implemented repository controls include single-use sign-in links, session controls, per-user authorization, forced row-level security on user-owned tables, and a separate administrator token for detailed operational health.

Implemented control

03

Data protection

Implemented repository controls include short-lived signed media links, metadata stripping, privacy-bounded product events, optional consent controls, deletion routes, export routes, and privacy receipts.

Launch gate

04

Testing and readiness

Cross-account authorization checks, dependency and software-bill-of-materials scanning, security testing, independent penetration testing, and incident exercises.

Inspect the staff-access boundary

Support staff should not need body data to verify identity. Sensitive administrative access is intended to be time-limited, logged, role-restricted, and approved for a stated task.

Inspect the vendor boundary

Required work includes vendor due diligence, training restrictions, deletion verification, incident-notification terms, and exit procedures before vendors can handle product data.

Inspect incident readiness

The launch program requires severity levels, ownership, paging, containment, evidence handling, escalation, notification review, recovery, exercises, and post-incident learning.

Report a concern

Start with a safe description.

Email [email protected] with the subject "Security report." Name the affected page or feature. Do not include credentials, capture media, measurements, or personal records in the first email.

The repository has a documented security control baseline. Independent penetration testing and a formal vulnerability disclosure process remain operational gates.

For component availability, read the service status page. Alex Folzi does not publish uptime percentages on the service status page.