Security
What the Wall prevents, what it cannot, and how your data is kept.
Entitlement
- Entitlement is a JWT signed with your workspace's ES256 key, bound to one device, valid for 15 minutes. The private key never leaves the Wall; the extension only verifies.
- Every request that can change access is signed by a key made on the device, which cannot be exported.
- The extension link that makes a signed-in device trusted is stored as a hash, bound to one device, narrow in scope, expiring and revocable. The buyer's browser session never reaches the extension.
- Licence keys are stored as hashes. Devices per licence are capped.
- Trials need a verified address from a non-disposable domain, one per inbox per tool, whether the Wall starts it or Stripe does at checkout. The inbox is kept as a keyed hash.
What cannot be prevented
The extension runs on the buyer's machine. Someone who edits its JavaScript can skip a check made inside it. What the Wall does — counting uses, issuing tokens, authorising downloads — cannot be skipped; a feature computed entirely inside the extension is protected only as well as any client-side software.
Your workspace
- Buyers live in a pool per workspace; another workspace cannot read them.
- API keys are stored as hashes and shown once.
- Webhook secrets are held by Svix.
- The signing key is sealed at rest and revealed only in an export you request.
Buyers' data
- Buyer data is stored in the EU: the database in Stockholm, the application in Frankfurt, email sent from Stockholm.
- From a customer's page you can download a person's data and erase them. Erasure removes the person and keeps purchases for the tax record.
- Deleting an account, by the buyer, cancels their subscriptions and ends their sign-in; licences bought under the address remain as purchases.
The record of what is promised and what enforces it is in the Wall's SECURITY.md.