الانتقال إلى المحتوى
HIDDENIO

Security

آخر تحديث: 2026-09-01
## Responsible disclosure We welcome reports from security researchers and act on them in good faith. - **Contact:** **security@hiddenio.com** (placeholder until a dedicated address is published). - **Scope:** the hiddenio.com website, the /api/v1 API, subscription endpoints and the crawler infrastructure. Reports about third-party servers that merely appear in the index are out of scope. - **What to include:** a description, reproduction steps, impact assessment and, if possible, a proof of concept. Format does not matter. - **Safe harbor:** we will not pursue action against researchers who test with reasonable care, avoid privacy destruction and service degradation, and report promptly. - **Process:** we acknowledge within a few business days, triage, fix, and can credit you publicly if you wish. ## Security model (summary) - **No secrets in the browser.** All /tools utilities run client-side; nothing you paste leaves your machine. - **Authentication** uses httpOnly, signed session cookies (short-lived access token + refresh); passwords are stored only as modern password hashes. Optional TOTP two-factor is available for accounts. - **Personal feed tokens and API keys** are stored hashed; they are displayed exactly once at creation or rotation and can be revoked instantly. - **Least privilege.** Admin actions go through role checks and are written to an audit log. - **Crawler isolation.** Fetching happens in an isolated pipeline with SSRF validation, so sources cannot reach internal services. ## Caveat An index of public data cannot vouch for the content it lists; the security of any third-party server is that server's responsibility, not ours. See the [disclaimer](/disclaimer).