Account and session protection
Passwords are stored as one-way hashes. Authenticated sessions use protected HTTP-only cookies, signed tokens, token revocation, rate limits, and server-side identity validation. Sensitive dashboard and API routes require authentication.
Tenant and receipt isolation
Receipt, category, classifier, notification, and integration queries are scoped to the authenticated account. Composite database constraints reinforce tenant ownership for receipt-classifier relationships.
Images, integrations, and providers
Receipt files are stored in private object storage and served through authenticated application routes. Bot webhooks and internal service calls use validation, allow-listed destinations, size limits, and shared-secret controls. Payment card details are handled by the payment provider rather than stored by GoSlip.
Monitoring and recovery
Health checks, error monitoring, authentication events, durable queues, retries, and bounded cleanup jobs help detect and recover from failures. Security-relevant logs must never include passwords, tokens, cookie values, or full receipt content.
Report a vulnerability
Use the GoSlip support channel and clearly label the message Security report. Include reproducible steps and impact, but do not access other users' data, disrupt production, or publish a vulnerability before the team has had a reasonable opportunity to investigate.