Security practices
This page describes the security measures FeedCentral currently has in place. It is not a compliance certification or an audit report.
Credentials
API credentials are scoped: each credential is granted only the specific access it needs, not blanket account-wide access. Credential secrets are never stored in reversible or plaintext form.
Transport & browser protections
All human-facing pages are served with standard browser security headers (content-type sniffing protection, clickjacking protection, a restrictive content security policy) and are expected to run over HTTPS.
Abuse protection
Authentication and account-recovery endpoints, as well as the public contact form, are rate-limited to reduce automated abuse.
Reporting a security issue
If you believe you've found a security issue, please use the contact form and select the Security topic. We ask that you avoid accessing or modifying data that isn't your own while investigating.