1. Security Practices
DWL Accounts is designed to use HTTPS, secure Auth.js cookies, Google OAuth where selected, first-party email/password authentication with Argon2id password hashes, WebAuthn passkeys, server-side Supabase service access, restricted client access for sensitive account tables, audit events, provider access controls, environment-secret controls, and deployment controls through Vercel. The browser should receive only public Supabase URL and publishable key values. Payment card data, where purchases are enabled, should be handled by the payment processor rather than stored directly by DWL Accounts.
2. User Security Responsibilities
Keep your email account, devices, payment methods, passkeys, passwords, recovery methods, and browser sessions secure. Use unique passwords, passkeys where available, device-level security, and prompt sign-out on shared devices. Report suspected compromise, unauthorized purchases, or suspicious security events to security
3. Responsible Disclosure
Send suspected vulnerabilities to security
4. Security Incidents
If an incident affects personal information, account security, payment metadata, or connected-app access, DWL Accounts will investigate and provide user, provider, payment processor, connected-app, or regulator notice where required by applicable law or provider rules. Absolute security is not promised.
5. Security Boundaries And No Warranty
Public security statements describe intended controls and do not create a warranty, guarantee, certification, audit representation, or promise that a specific configuration is active at all times. Do not rely on DWL Accounts for emergency, life-safety, regulated healthcare, regulated financial, or mission-critical workflows unless a separate signed agreement and reviewed implementation expressly say otherwise.