Pyronpyronstudio.Open Studio
SECURITY

Security is built into the platform architecture.

Pyron is designed to reduce attack surface at every layer — not to eliminate risk entirely, which is not achievable, but to handle it responsibly.

Authentication

Better Auth with verified email required. Sessions use secure cookies. Password minimum 12 characters. Rate limiting on all auth endpoints.

Authorization

Every API request checks workspace membership and role capabilities server-side. Frontend permissions are for UX only — never trusted for access control.

CSRF protection

All mutating requests verify the request origin matches the configured app domain.

Input validation

All inputs are validated with Zod schemas before reaching the database. SQL injection is prevented by parameterized queries via Drizzle ORM.

Credential security

Third-party OAuth tokens (e.g. Instagram) are encrypted at rest using AES-256-GCM with unique nonces and workspace/account binding. API secrets are never exposed to the browser.

Responsible disclosure

If you discover a vulnerability in Pyron, please contact us privately before publishing. We will investigate and respond before any public disclosure.

View trust center