Last updated: 2026-06-19

Security

This page documents our current security posture honestly — including the gaps. We're in a private alpha and prefer transparency over marketing claims.

Transport

Authentication

Sandbox isolation

Known gaps (alpha)

We'd rather tell you than have you discover them in production:

Reporting a vulnerability

If you find a security issue, please report it privately. Don't post it publicly until we've had a chance to address it.

We aim to acknowledge within 48 hours and provide a fix or mitigation timeline within 7 days. No bug bounty during alpha, but we'll publicly credit you (if you want) in the Changelog.

Safe harbor

If you act in good faith, focus on the sandstack service, avoid privacy violations, and give us reasonable time to respond, we will not pursue legal action for testing.