Trust

Security

OwnMode uses client isolation, database row policies, versioned events, and server-verified entitlements.

Application controls

Authentication uses short-lived sessions and PKCE. User data is restricted with row-level security. Security-sensitive commands re-check authentication and authorization when they run.

Data and operational controls

Transport encryption, webhook verification, idempotency keys, request limits, release channels, and correlation identifiers support prevention and investigation. Production credentials are kept outside application source and public client bundles.

Reporting

Report a suspected security issue through the support form. Include the affected page, time, and steps to reproduce, but do not include passwords, private session content, or store receipts.