Skip to content

Security

FlagWire treats feature delivery as production infrastructure. Current controls include:

  • verified email and optional Google/GitHub sign-in;
  • bot protection and database-backed rate limiting for sensitive email flows;
  • secure, HTTP-only session cookies with trusted-origin enforcement;
  • organization and project isolation with owner, admin, and member authorization;
  • exact allowed-origin lists for browser keys, plus per-key and per-IP runtime abuse controls;
  • non-reversible SDK-key storage, one-time secret display, and revocation propagation;
  • bounded evaluation context and privacy-safe diagnostic dimensions;
  • immutable configuration versions, required Production review comments, idempotent publication, rollback, and audit history;
  • raw-body signature verification, replay protection, and ordering controls for payment webhooks;
  • sampled production logs, tracing disabled by default, synthetic monitoring, backups, and tested recovery procedures.

Browser keys identify a public client and are not secrets. Exact-origin enforcement reduces accidental misuse but cannot replace server-side authorization for sensitive decisions. Never put secrets in browser-delivered flags or remote configuration. Use server keys only in trusted server environments.

FlagWire does not currently claim a third-party security certification, penetration-test attestation, contractual SLA, or formal bug-bounty program.

Send a concise report to security@flagwire.dev with the affected surface, reproduction steps, and impact. Do not access other customers, retain personal data, degrade the Service, or run destructive/load testing. We will acknowledge reports on a best-effort basis and coordinate remediation and disclosure when appropriate.

Operational availability is published on the FlagWire status page.