Authentication
Better Auth with verified email required. Sessions use secure cookies. Password minimum 12 characters. Rate limiting on all auth endpoints.
Pyron is designed to reduce attack surface at every layer — not to eliminate risk entirely, which is not achievable, but to handle it responsibly.
Better Auth with verified email required. Sessions use secure cookies. Password minimum 12 characters. Rate limiting on all auth endpoints.
Every API request checks workspace membership and role capabilities server-side. Frontend permissions are for UX only — never trusted for access control.
All mutating requests verify the request origin matches the configured app domain.
All inputs are validated with Zod schemas before reaching the database. SQL injection is prevented by parameterized queries via Drizzle ORM.
Third-party OAuth tokens (e.g. Instagram) are encrypted at rest using AES-256-GCM with unique nonces and workspace/account binding. API secrets are never exposed to the browser.
If you discover a vulnerability in Pyron, please contact us privately before publishing. We will investigate and respond before any public disclosure.