FeedCentral
Security

Security practices

This page describes the security measures FeedCentral currently has in place. It is not a compliance certification or an audit report.

Credentials

API credentials are scoped: each credential is granted only the specific access it needs, not blanket account-wide access. Credential secrets are never stored in reversible or plaintext form.

Transport & browser protections

All human-facing pages are served with standard browser security headers (content-type sniffing protection, clickjacking protection, a restrictive content security policy) and are expected to run over HTTPS.

Abuse protection

Authentication and account-recovery endpoints, as well as the public contact form, are rate-limited to reduce automated abuse.

Reporting a security issue

If you believe you've found a security issue, please use the contact form and select the Security topic. We ask that you avoid accessing or modifying data that isn't your own while investigating.