Skip to content

Security

Private by default, and provably so

Mind maps hold strategy, salaries and half-formed ideas people are not ready to defend. We treat them accordingly.

Authorisation on the server

Every read and write resolves through one permissions module. The interface reflects what you can do; it never decides it.

Sessions you can revoke

Session cookies are opaque, HTTP-only and same-site. Only a SHA-256 hash is stored, so a database copy cannot be replayed.

Careful account handling

Passwords are hashed with bcrypt. Reset links are single-use, expire in an hour, and invalidate every existing session.

Uploads treated as hostile

Size limits, MIME validation and a restrictive content policy on the serving route, so an uploaded file can never execute in our origin.

Rate limiting

Authentication, invitations, uploads, imports and AI endpoints are all rate-limited per IP and per account.

Your data stays portable

Export any map as JSON, Markdown, PDF, SVG or PNG at any time — including after you downgrade or cancel.

In detail

The questions security reviewers ask

Reporting a vulnerability

If you believe you have found a security issue, please tell us before telling anyone else. Write to contact@untangling.app with enough detail to reproduce it. We will confirm receipt within two working days, keep you updated while we investigate, and credit you when the fix ships if you would like us to.

Please do not run automated scanners against production, access accounts that are not yours, or degrade the service for other people while testing.

Questions we have not answered?

Enterprise customers get a full architecture walkthrough and a completed security questionnaire.

See enterprise controls
Security · Untangling