Runtime credential boundary
A one-time installation code proves one exact origin. Short-lived, origin-bound credentials then permit only scoped configuration, heartbeat, summarized run, rescue outcome and deliberate rescue-request operations. They grant no dashboard, workspace, billing or cross-site access.
Tenant and mutation controls
Supabase Row Level Security checks workspace membership for dashboard data. Server mutations independently resolve the actor and workspace, enforce ownership/plan limits, and use narrowly granted database functions for transactional operations.
Data minimization
Runtime records exclude request bodies, authorization values, original form contents, arbitrary HTML, keystrokes and session replay. Errors and provider states are normalized. Prohibited rescue fields are blocked by a purpose allowlist and submitted secret-like values are rejected or quarantined.
Billing and operations
Paddle webhook signatures are verified against the raw request body and events are processed idempotently. Delivery queues, reconciliation, readiness checks, monitored jobs, backups and rollback procedures reduce silent failures. Secrets remain server-only and are classified for sandbox/production consistency.
Responsible disclosure
Send vulnerability reports to security@siteairbag.com with reproduction steps and impact. Do not access another customer's data, use destructive testing, degrade availability, or retain personal data. We target acknowledgement within two business days and will coordinate remediation updates. This is not a bug-bounty promise.
Related documents and contact
Terms · Privacy · DPA · Subprocessors · Acceptable use · Storage and cookies · Cancellation and refunds · Security
Support: support@siteairbag.com · Privacy: privacy@siteairbag.com · Security: security@siteairbag.com