Security
🚫
Policy violations today
—
actions blocked by your rules
📋
Total actions logged
—
all time
Policy violations — last 7 days
Loading...
Platform security
✓
Server-side sessions in PostgreSQL
Sessions stored in your database — not in cookies or localStorage. Cannot be tampered with client-side.
✓
Brute force protection
Login is rate-limited to 10 attempts per 15 minutes per IP. Attackers cannot guess passwords at scale.
✓
HTTP-only cookies
Session cookies cannot be accessed by JavaScript. XSS attacks cannot steal your session.
✓
CSRF protection — SameSite strict
Cookies are never sent on cross-site requests. Cross-site request forgery attacks are blocked automatically.
✓
Helmet security headers
X-Frame-Options, X-Content-Type-Options and other critical headers set automatically on every response.
✓
Passwords encrypted with bcrypt
Passwords are hashed with bcrypt cost factor 10. Plain text passwords are never stored anywhere.
✓
Customer data fully isolated
Every log and rule query is scoped to the authenticated customer. No customer can ever see another customer's data.
○
HTTPS — enable on production deploy
Set cookie.secure = true in your server config when you deploy with HTTPS.