SECURITY BY DESIGN

Trust starts with the foundations.

Website files, client access, and payments need deliberate boundaries. Here is how each one is kept today, and what is still being hardened before hosting opens to everybody.

01
Accounts with clear boundaries

Database-backed sessions, email verification for developer accounts, invite-only magic links for clients, and server-side role checks.

In the foundation
02
Protection at the app boundary

Content Security Policy, host-only session cookies, request-origin checks, authentication rate limits, and a TLS approval endpoint that denies unverified domains.

In the foundation
03
An isolated hosting design

Hosted sites live on a separate registrable domain from the application and are served as plain files by the edge, outside the application and its cookie scope. Nothing a site contains is ever executed on the server. The servers are in Germany.

In the foundation
04
Safe uploads and content

Uploads are read strictly: path traversal, symlinks, unsupported file types and oversized archives are refused before anything is written. Pictures a site owner uploads are re-encoded, and what they write is reduced to text, bold, italic and links.

In the foundation
05
Payments through Stripe

Card details are typed into Stripe's own fields and never reach WireSwan. A payment counts only when Stripe says so in a signed message, which is read back from Stripe and processed once — never because a browser said it was paid.

In the foundation
06
Operations that earn trust

Backups with restore tests run on the server. A second copy kept somewhere else, abuse tooling and an outside review are still to come. This is a young service run by one person, not an audited one.

Still being hardened
Back to WireSwan