Security Privacy

PromptPress Documentation

Back

Promptesso uses layered controls across authentication, authorization, account scoping, and request protection.

Security Principles

  • Least privilege by default.
  • Workspace-bound access decisions.
  • Safe handling of untrusted input.
  • Minimal sensitive data exposure in user-facing errors.

Access and Route Protection

Core protections include:

  • Authentication on protected routes.
  • Role checks on privileged actions.
  • CSRF protection on state-changing requests.
  • Secure session and cookie handling.

Workspace Isolation

Expected behavior:

  • Cross-workspace data access is blocked for regular users.
  • Forged account headers are rejected.
  • Elevated operations are separated into explicit privileged paths.

Input and Content Safety

PromptPress applies validation and sanitization to reduce:

  • Script injection risks.
  • Malformed payload handling issues.
  • Unsafe URL and file input patterns.
  • Unexpected content execution behavior.

Security Headers and Browser Controls

Common protections include:

  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • CSP-related controls where configured

Privacy-Safe Operations

Production-safe behavior should avoid exposing:

  • Internal stack traces.
  • Secret values in client output.
  • Unnecessary personal data in logs and payloads.

Authenticated users can request a privacy export from personal settings. The
export bundles account, membership, authored content, comments, saved articles,
and notification records while stripping token-like auth metadata before the
JSON file is returned.

Runtime content, tenant sites, newsletters, campaign data, billing state, and
workspace records are driven by the application database and storage layer. AI
features, payment processing, email delivery, observability, and hosting may
use configured service providers as described in the public Privacy Policy.

Only workspace owners, billing owners, or other authorized administrators should
manage subscriptions, payment methods, and purchased credit balances for a
workspace. Members use the workspace entitlements granted to them through their
role.

Team Security Checklist

  • Review owner/admin memberships regularly.
  • Remove stale invites quickly.
  • Enforce stronger auth requirements for sensitive roles where policy requires.
  • Keep an incident trail with account, route, UTC time, and correlation ID.

Reporting Suspected Issues

Include:

  • Workspace identifier.
  • User role and affected route.
  • UTC timestamp.
  • Correlation ID if available.
  • Minimal reproduction steps.

Related Docs