Current protection
HTTPS production delivery, HttpOnly sessions, same-origin write checks, strict content security policy, access controls, bounded requests and application rate limits protect the service. TOTP second-factor verification is required for admin controls and can be enabled for user accounts.
Disclosure
Report a potential vulnerability through support with “Security” selected. Describe the affected feature and reproduction steps without including passwords, tokens or unrelated personal data. Do not extract other people’s records, disrupt the service or make threats.
Scope
These measures do not claim certification, an independent penetration test, complete DDoS protection or an activated Cloudflare managed WAF rule set. Infrastructure firewall configuration and incident response ownership require separate operator verification.