Security
最后更新: 2026-09-01
## Responsible disclosure
We welcome reports from security researchers and act on them in good faith.
- **Contact:** **security@hiddenio.com** (placeholder until a dedicated address is published).
- **Scope:** the hiddenio.com website, the /api/v1 API, subscription endpoints and the crawler
infrastructure. Reports about third-party servers that merely appear in the index are out of scope.
- **What to include:** a description, reproduction steps, impact assessment and, if possible, a proof
of concept. Format does not matter.
- **Safe harbor:** we will not pursue action against researchers who test with reasonable care, avoid
privacy destruction and service degradation, and report promptly.
- **Process:** we acknowledge within a few business days, triage, fix, and can credit you publicly if
you wish.
## Security model (summary)
- **No secrets in the browser.** All /tools utilities run client-side; nothing you paste leaves your
machine.
- **Authentication** uses httpOnly, signed session cookies (short-lived access token + refresh);
passwords are stored only as modern password hashes. Optional TOTP two-factor is available for
accounts.
- **Personal feed tokens and API keys** are stored hashed; they are displayed exactly once at
creation or rotation and can be revoked instantly.
- **Least privilege.** Admin actions go through role checks and are written to an audit log.
- **Crawler isolation.** Fetching happens in an isolated pipeline with SSRF validation, so sources
cannot reach internal services.
## Caveat
An index of public data cannot vouch for the content it lists; the security of any third-party server
is that server's responsibility, not ours. See the [disclaimer](/disclaimer).