Security
What we protect
- Account credentials with scrypt password hashes.
- Session tokens hashed at rest and sent to the browser as httpOnly cookies.
- Private My Spools with server-side ownership checks.
- Public QR projections that omit notes, locations and account identifiers.
- Payment card data handled by Stripe — not stored on OpenFilament servers.
Responsible disclosure
Report vulnerabilities privately to the configured security contact. Do not publicly disclose secrets, exploits against live users or production credentials. Allow reasonable time for remediation before public discussion.