Security
How Found keeps your accounts safe. Found a problem? See the end of this page.
Signing in
- The app sits behind an email code from Cloudflare, then your password.
- Sessions are signed, live in a secure cookie scripts can't read, and end after 30 days. You can sign out everywhere at once.
- Too many wrong passwords from one place and sign-in waits 15 minutes. A flood from everywhere pauses it for an hour.
Your keys
- Passwords and keys are encrypted with AES-256 before they're saved.
- Money and chat connections use read-only keys you make, so they can't charge, pay or post.
- Disconnecting deletes the key straight away.
The website
- Runs only our own code. No outside scripts, and it can't be embedded in other sites.
- Changes come only from our own pages, so another site can't make Found do anything.
- The admin area is separate, on its own address, behind its own sign-in.
Before anything ships
- Every change is checked for keys, passwords and personal details before it goes live.