Promptesso uses layered controls across authentication, authorization, account scoping, and request protection.
Security Principles
- Least privilege by default.
- Workspace-bound access decisions.
- Safe handling of untrusted input.
- Minimal sensitive data exposure in user-facing errors.
Access and Route Protection
Core protections include:
- Authentication on protected routes.
- Role checks on privileged actions.
- CSRF protection on state-changing requests.
- Secure session and cookie handling.
Workspace Isolation
Expected behavior:
- Cross-workspace data access is blocked for regular users.
- Forged account headers are rejected.
- Elevated operations are separated into explicit privileged paths.
Input and Content Safety
PromptPress applies validation and sanitization to reduce:
- Script injection risks.
- Malformed payload handling issues.
- Unsafe URL and file input patterns.
- Unexpected content execution behavior.
Security Headers and Browser Controls
Common protections include:
X-Frame-OptionsX-Content-Type-OptionsReferrer-Policy- CSP-related controls where configured
Privacy-Safe Operations
Production-safe behavior should avoid exposing:
- Internal stack traces.
- Secret values in client output.
- Unnecessary personal data in logs and payloads.
Authenticated users can request a privacy export from personal settings. The
export bundles account, membership, authored content, comments, saved articles,
and notification records while stripping token-like auth metadata before the
JSON file is returned.
Runtime content, tenant sites, newsletters, campaign data, billing state, and
workspace records are driven by the application database and storage layer. AI
features, payment processing, email delivery, observability, and hosting may
use configured service providers as described in the public Privacy Policy.
Only workspace owners, billing owners, or other authorized administrators should
manage subscriptions, payment methods, and purchased credit balances for a
workspace. Members use the workspace entitlements granted to them through their
role.
Team Security Checklist
- Review owner/admin memberships regularly.
- Remove stale invites quickly.
- Enforce stronger auth requirements for sensitive roles where policy requires.
- Keep an incident trail with account, route, UTC time, and correlation ID.
Reporting Suspected Issues
Include:
- Workspace identifier.
- User role and affected route.
- UTC timestamp.
- Correlation ID if available.
- Minimal reproduction steps.