Skip to content
Menu

Security & privacy by design

How it works

Security & privacy by design

Everything arriving from the network is hostile until proven otherwise.

Federation

Signed or rejected

Every incoming message must carry a valid signature.

Right domain

The author must belong to the domain that signs.

No SSRF

Remote fetches avoid private IPs, with size and time limits.

Clean HTML

Remote content is sanitised with an allowlist.

Encrypted envelopes

Private diaspora* payloads are validated after decryption.

Rate limits

Per server and per account, backed by Redis.

Only the Family aspect can see the post

One gate for visibility

Who can see a post is decided by a single function, canView. Feeds, search, threads, media and federation all go through it.

Media of non-public posts is served through signed, expiring links.

Your account

  • Passwords hashed with Argon2id
  • Passkeys (WebAuthn) and TOTP two-factor login with recovery codes
  • HttpOnly, SameSite session cookies; scoped OAuth tokens for apps
  • Full export of your data, and account deletion that reaches other servers
  • Move your account to another server and keep your followers

Moderation

Reports

Report posts and accounts, also to their home server.

Blocks

Block or silence people and whole domains.

Sign-up control

Open, by invitation or with approval. Every admin action is logged.

Found a vulnerability? Please write to [email protected] before making it public.