Security
Security
Section titled “Security”FlagWire treats feature delivery as production infrastructure. Current controls include:
- verified email and optional Google/GitHub sign-in;
- bot protection and database-backed rate limiting for sensitive email flows;
- secure, HTTP-only session cookies with trusted-origin enforcement;
- organization and project isolation with owner, admin, and member authorization;
- exact allowed-origin lists for browser keys, plus per-key and per-IP runtime abuse controls;
- non-reversible SDK-key storage, one-time secret display, and revocation propagation;
- bounded evaluation context and privacy-safe diagnostic dimensions;
- immutable configuration versions, required Production review comments, idempotent publication, rollback, and audit history;
- raw-body signature verification, replay protection, and ordering controls for payment webhooks;
- sampled production logs, tracing disabled by default, synthetic monitoring, backups, and tested recovery procedures.
Browser keys identify a public client and are not secrets. Exact-origin enforcement reduces accidental misuse but cannot replace server-side authorization for sensitive decisions. Never put secrets in browser-delivered flags or remote configuration. Use server keys only in trusted server environments.
FlagWire does not currently claim a third-party security certification, penetration-test attestation, contractual SLA, or formal bug-bounty program.
Report a vulnerability
Section titled “Report a vulnerability”Send a concise report to security@flagwire.dev with the affected surface, reproduction steps, and impact. Do not access other customers, retain personal data, degrade the Service, or run destructive/load testing. We will acknowledge reports on a best-effort basis and coordinate remediation and disclosure when appropriate.
Operational availability is published on the FlagWire status page.