Security

Report a vulnerability privately to security@litcollab.online.

Responsible disclosure

Please include reproducible steps and avoid accessing, changing, or retaining other users' data. Do not publish a vulnerability before we have had a reasonable opportunity to investigate and remediate it. We will acknowledge good-faith reports and coordinate remediation.

Controls

OAuth tokens are encrypted at rest using authenticated encryption. Secrets and tokens are never returned to the browser or included in audit logs. The service uses server-side authorization, secure cookies, request-origin checks, rate limits, and restrictive HTTP security headers.