Trust
Security
Last updated
Stoqlab is built from public data, but the accounts, API keys and lists of our customers are not public. This page describes how we protect them and how to reach us if you find a problem.
Infrastructure
- The Service runs on servers hosted in the European Union.
- All traffic is served over HTTPS, with HTTP Strict Transport Security on every host.
- Every page is sent with a strict Content-Security-Policy, and the Service cannot be framed by other sites.
- The public site, the dashboard and the API run on separate hosts with separate routing; the API host serves JSON only.
Accounts and API keys
- Accounts are created by our team; self-service sign-up is closed.
- Passwords are stored as salted bcrypt hashes. Sign-in attempts are rate-limited per account and per network address.
- API keys are shown once, stored only as hashes, can be revoked instantly from the dashboard and show when they were last used.
- Keys carry explicit permissions: read-only by default, with write access to your own lists only when you choose it.
- MCP keys for AI assistants are read-only, work only on the MCP server, and expire automatically.
- The API is rate-limited per account and per network address, with a separate limit on failed authentications.
Data
- Saved lists are private to the account that created them.
- Contact-form submissions store a keyed one-way hash of the network address, never the raw address.
- Operational pages are restricted to a small number of administrators.
- The crawler and the web application use separate database permissions: the crawler cannot read customer tables.
Our crawler
StoqlabBot only reads public files, follows robots.txt, refuses to connect to private or internal network addresses, and caps the size of every download. More on the StoqlabBot page.
Reporting a vulnerability
If you believe you have found a security issue in Stoqlab, email security@stoqlab.com with the steps to reproduce it. Please give us reasonable time to fix the issue before disclosing it, do not access data that is not yours, and do not degrade the Service for others while testing. We will acknowledge your report and keep you informed. We do not run a paid bug bounty at this time.