Security
What we protect
- Account credentials (scrypt password hashes; never plaintext).
- Session tokens hashed at rest.
- Private My Spools with server-side ownership checks.
- Public QR projections that omit notes, locations and account identifiers.
Responsible disclosure
Report vulnerabilities privately to info@openfilament.nl. Do not publicly disclose secrets, exploits against live users, or production credentials. Allow a reasonable time for remediation before public discussion.