Current controls
- Traffic is served over HTTPS through Cloudflare.
- Authentication is handled server-side; protected application routes require an authenticated account.
- Workspace and subject permissions are checked on the server, not only hidden in the interface.
- Files use organization-scoped storage keys rather than public bucket paths.
- Production request and error logging is enabled for diagnosis and security review.
- Secrets such as the OpenAI API key are supplied through the deployment environment rather than shipped to the browser.
What we haven't built yet
Cotable is a small beta. There's no public security audit, penetration test report, self-serve account deletion, status page, or published incident history yet. This page changes as those land.
Report a vulnerability
Email hello@cotable.ai with “Security report” in the subject. Include the affected URL, impact, and reproduction steps. Do not access another family's data, disrupt the service, or publish private information while testing.