Security
Private by default, and provably so
Mind maps hold strategy, salaries and half-formed ideas people are not ready to defend. We treat them accordingly.
Authorisation on the server
Every read and write resolves through one permissions module. The interface reflects what you can do; it never decides it.
Sessions you can revoke
Session cookies are opaque, HTTP-only and same-site. Only a SHA-256 hash is stored, so a database copy cannot be replayed.
Careful account handling
Passwords are hashed with bcrypt. Reset links are single-use, expire in an hour, and invalidate every existing session.
Uploads treated as hostile
Size limits, MIME validation and a restrictive content policy on the serving route, so an uploaded file can never execute in our origin.
Rate limiting
Authentication, invitations, uploads, imports and AI endpoints are all rate-limited per IP and per account.
Your data stays portable
Export any map as JSON, Markdown, PDF, SVG or PNG at any time — including after you downgrade or cancel.
In detail
The questions security reviewers ask
Reporting a vulnerability
If you believe you have found a security issue, please tell us before telling anyone else. Write to contact@untangling.app with enough detail to reproduce it. We will confirm receipt within two working days, keep you updated while we investigate, and credit you when the fix ships if you would like us to.
Please do not run automated scanners against production, access accounts that are not yours, or degrade the service for other people while testing.
Questions we have not answered?
Enterprise customers get a full architecture walkthrough and a completed security questionnaire.
See enterprise controls