Security

Security practices for ForeverLink workspaces and public redirects.

Authentication

Argon2id/bcrypt password hashing, optional TOTP 2FA, single-use recovery codes, progressive lockouts after failed logins.

Sessions

HttpOnly cookies, SameSite=Lax, Secure in production, inactivity timeout, session regeneration after login.

Application

CSRF tokens on POST forms, prepared statements, tenant-scoped queries, security headers on admin surfaces.

Redirects

Only https destinations are accepted. Private and localhost hosts are rejected.

Report a vulnerability

Responsible disclosure via our contact form — please include steps to reproduce.

Contact security
Start 15-day
free trial