SECURITY AT MONELYRA

Trust is a system.
Not a slogan.

Monelyra combines preventative controls, traceable administration and recoverable releases. No online service is invulnerable, so we also publish a clear route for responsible reports.

RESPONSIBLE DISCLOSURE

Found something that may put people or campaigns at risk?

Email the security team. Include the affected URL, reproduction steps, impact and a safe way to contact you. Please do not access, alter or retain data that is not yours.

01

Account protection

Strong password hashing, role checks, secure session settings, CSRF protection and rate limits protect sensitive account actions.

02

Private campaign media

Artwork is MIME-validated, randomized and stored outside the public web path or in a private R2 bucket. Access is role-checked and R2 links expire.

03

Payment boundaries

Optional Stripe Checkout and Connect use hosted financial onboarding. Webhooks are verified against the raw signed payload and processed idempotently.

04

Release integrity

Release files are checked against SHA-256 digests, executable files outside the manifest are rejected and the installed manifest is sealed.

05

Recoverable updates

Preflight checks, database and application backups, maintenance mode and automatic recovery protect deployment changes.

06

Honest limits

These controls reduce risk; they do not guarantee absolute security. Independent penetration testing, legal review and operational monitoring remain required before high-value production use.

Machine-readable contact

Security tools can discover the same reporting route at /.well-known/security.txt.