Trust
Security
OwnMode uses client isolation, database row policies, versioned events, and server-verified entitlements.
Application controls
Authentication uses short-lived sessions and PKCE. User data is restricted with row-level security. Security-sensitive commands re-check authentication and authorization when they run.
Data and operational controls
Transport encryption, webhook verification, idempotency keys, request limits, release channels, and correlation identifiers support prevention and investigation. Production credentials are kept outside application source and public client bundles.
Reporting
Report a suspected security issue through the support form. Include the affected page, time, and steps to reproduce, but do not include passwords, private session content, or store receipts.