How we protect your account
Sign-in works by email link, and Stripe holds every card and bank account. We hold no passwords and no card numbers.
Six controls
| Control | How it works |
|---|---|
| Sign-in | A single-use email link, valid for 15 minutes, starts a session of 30 days in an HttpOnly cookie. |
| Payments | Stripe collects every card and bank detail, and Ironstone stores only Stripe's identifiers. |
| Mailbox passwords | An app password is sealed with AES-GCM when it is saved, and only the sending machine opens it. |
| Transport | Every page and every site loads over HTTPS through Cloudflare. |
| Takedown | A preview comes down in 1 click, and the takedown deletes its files. |
| Webhooks | Stripe's events carry a signature, and a replayed event older than 5 minutes is refused. |
Updated September 26, 2026. The sub-processors page names every company that processes data, and the privacy policy says what we keep.
Questions
Do I need to buy anything for security?
No. Every page and every site loads over a secure connection, and certificates are issued and renewed for you.
Who holds card and bank details?
Our payment processor, Stripe. We store only its identifiers, never a card or bank number.
How long does a sign-in link work?
Once, within 15 minutes. It starts a session of 30 days, and there is no password to steal.
Can a change to a site be undone?
Yes. Every change is kept as a version for 90 days, and any version comes back in one click.
What happens when a preview is taken down?
Its address shows a notice at once, and its files are deleted from storage.
Report an issue
Use the contact form with the topic "A security issue". Include the page or feature, what you saw, and how to repeat it. We answer each report within 2 business days.
For a site that should come down, the takedown page is faster, and the status page lists every incident.