How it works
Security & privacy by design
Everything arriving from the network is hostile until proven otherwise.
Federation
Signed or rejected
Every incoming message must carry a valid signature.
Right domain
The author must belong to the domain that signs.
No SSRF
Remote fetches avoid private IPs, with size and time limits.
Clean HTML
Remote content is sanitised with an allowlist.
Encrypted envelopes
Private diaspora* payloads are validated after decryption.
Rate limits
Per server and per account, backed by Redis.

One gate for visibility
Who can see a post is decided by a single function, canView. Feeds, search, threads, media and federation all go through it.
Media of non-public posts is served through signed, expiring links.
Your account
- Passwords hashed with Argon2id
- Passkeys (WebAuthn) and TOTP two-factor login with recovery codes
- HttpOnly, SameSite session cookies; scoped OAuth tokens for apps
- Full export of your data, and account deletion that reaches other servers
- Move your account to another server and keep your followers
Moderation
Reports
Report posts and accounts, also to their home server.
Blocks
Block or silence people and whole domains.
Sign-up control
Open, by invitation or with approval. Every admin action is logged.
Found a vulnerability? Please write to [email protected] before making it public.
