Toolaby Wall

Security

What the Wall prevents, what it cannot, and how your data is kept.

Entitlement

  • Entitlement is a JWT signed with your workspace's ES256 key, bound to one device, valid for 15 minutes. The private key never leaves the Wall; the extension only verifies.
  • Every request that can change access is signed by a key made on the device, which cannot be exported.
  • The extension link that makes a signed-in device trusted is stored as a hash, bound to one device, narrow in scope, expiring and revocable. The buyer's browser session never reaches the extension.
  • Licence keys are stored as hashes. Devices per licence are capped.
  • Trials need a verified address from a non-disposable domain, one per inbox per tool, whether the Wall starts it or Stripe does at checkout. The inbox is kept as a keyed hash.

What cannot be prevented

The extension runs on the buyer's machine. Someone who edits its JavaScript can skip a check made inside it. What the Wall does — counting uses, issuing tokens, authorising downloads — cannot be skipped; a feature computed entirely inside the extension is protected only as well as any client-side software.

Your workspace

  • Buyers live in a pool per workspace; another workspace cannot read them.
  • API keys are stored as hashes and shown once.
  • Webhook secrets are held by Svix.
  • The signing key is sealed at rest and revealed only in an export you request.

Buyers' data

  • Buyer data is stored in the EU: the database in Stockholm, the application in Frankfurt, email sent from Stockholm.
  • From a customer's page you can download a person's data and erase them. Erasure removes the person and keeps purchases for the tax record.
  • Deleting an account, by the buyer, cancels their subscriptions and ends their sign-in; licences bought under the address remain as purchases.

The record of what is promised and what enforces it is in the Wall's SECURITY.md.

On this page