SECURITY BY DESIGN
Trust starts with the foundations.
Website files, client access, and payments need deliberate boundaries. Here is how each one is kept today, and what is still being hardened before hosting opens to everybody.
Database-backed sessions, email verification for developer accounts, invite-only magic links for clients, and server-side role checks.
Content Security Policy, host-only session cookies, request-origin checks, authentication rate limits, and a TLS approval endpoint that denies unverified domains.
Hosted sites live on a separate registrable domain from the application and are served as plain files by the edge, outside the application and its cookie scope. Nothing a site contains is ever executed on the server. The servers are in Germany.
Uploads are read strictly: path traversal, symlinks, unsupported file types and oversized archives are refused before anything is written. Pictures a site owner uploads are re-encoded, and what they write is reduced to text, bold, italic and links.
Card details are typed into Stripe's own fields and never reach WireSwan. A payment counts only when Stripe says so in a signed message, which is read back from Stripe and processed once — never because a browser said it was paid.
Backups with restore tests run on the server. A second copy kept somewhere else, abuse tooling and an outside review are still to come. This is a young service run by one person, not an audited one.