Account protection
Strong password hashing, role checks, secure session settings, CSRF protection and rate limits protect sensitive account actions.
SECURITY AT MONELYRA
Monelyra combines preventative controls, traceable administration and recoverable releases. No online service is invulnerable, so we also publish a clear route for responsible reports.
Email the security team. Include the affected URL, reproduction steps, impact and a safe way to contact you. Please do not access, alter or retain data that is not yours.
Strong password hashing, role checks, secure session settings, CSRF protection and rate limits protect sensitive account actions.
Artwork is MIME-validated, randomized and stored outside the public web path or in a private R2 bucket. Access is role-checked and R2 links expire.
Optional Stripe Checkout and Connect use hosted financial onboarding. Webhooks are verified against the raw signed payload and processed idempotently.
Release files are checked against SHA-256 digests, executable files outside the manifest are rejected and the installed manifest is sealed.
Preflight checks, database and application backups, maintenance mode and automatic recovery protect deployment changes.
These controls reduce risk; they do not guarantee absolute security. Independent penetration testing, legal review and operational monitoring remain required before high-value production use.
Security tools can discover the same reporting route at /.well-known/security.txt.