pr0d / SECURITY
Security.
pr0d sits between your users and your application, so its security is your security. This page says what we do and how to reach us if you find something.
Sign-in
- No passwords. pr0d signs people in with one-time email codes, social providers, passkeys, and QR approval. There is no password for pr0d to store or for an attacker to steal.
- Short-lived codes. Email codes are six digits, single-use, expire within minutes, and are rate-limited against guessing.
- Passkeys. Public-key credentials bound to the user’s device and to your application’s origin, which makes them resistant to phishing.
- Second factors. Applications can require an authenticator app (TOTP) or a passkey after an email or social sign-in.
Sessions
- Opaque tokens. Session tokens carry no claims. A leaked token exposes nothing about the user, and revoking it takes effect immediately because every check goes back to pr0d.
- One session per device. Users and applications can see every active session and end any of them without affecting the others.
- Activity-based renewal. Sessions renew while the user is active and lapse when they are not.
Infrastructure
- All traffic to pr0d is over TLS. pr0d.io, the docs, and the dashboard are served from Cloudflare’s network, which also sits in front of the API.
- Second-factor secrets and passkey material are stored encrypted, separately from account data.
- Access to production systems is limited to the people who operate them and requires multi-factor authentication.
Wallet
pr0d Wallet creates wallets inside your application and signs within the policies you define. Your application decides who can act and which operations are allowed; signing requests outside those policies are refused.
Reporting a vulnerability
If you find a security issue in pr0d, email security@pr0d.io with enough detail to reproduce it. We will acknowledge your report within two business days, keep you informed while we fix it, and credit you if you would like. Please give us a reasonable time to fix an issue before publishing it, and do not access other people’s data while testing.
We do not run a paid bug bounty at this stage.
Compliance
pr0d is in early access and has not yet completed a third-party audit such as SOC 2 or ISO 27001. We will publish reports here as they become available. Questions about our security practices: security@pr0d.io.