Policy violations today
—
actions blocked by your rules
Total actions logged
—
all time
Policy violations — last 7 days
Loading...
Platform security
Server-side sessions in PostgreSQL
Sessions stored in your database — not in cookies or localStorage. Cannot be tampered with client-side.
Brute force protection
Login is rate-limited to 10 attempts per 15 minutes per IP. Attackers cannot guess passwords at scale.
HTTP-only cookies
Session cookies cannot be accessed by JavaScript. XSS attacks cannot steal your session.
CSRF protection — SameSite strict
Cookies are never sent on cross-site requests. Cross-site request forgery attacks are blocked automatically.
Helmet security headers
X-Frame-Options, X-Content-Type-Options and other critical headers set automatically on every response.
Passwords encrypted with bcrypt
Passwords are hashed with bcrypt cost factor 10. Plain text passwords are never stored anywhere.
Customer data fully isolated
Every log and rule query is scoped to the authenticated customer. No customer can ever see another customer's data.
HTTPS — enable on production deploy
Set cookie.secure = true in your server config when you deploy with HTTPS.