Security is part of the product boundary.
MadePulse is designed to keep private shop data scoped to the authorized seller and to fail closed when a provider is not configured.
Private beta policy draft. Last updated: August 30, 2026.Engineering controls
- Database-backed sessions for connected application accounts
- Encrypted OAuth credentials with rotation support
- Server-resolved tenant and workspace isolation
- Secret-safe logging and minimized provider payload handling
- Read-only Etsy scope design
- No live provider calls in the public demo
Public-staging boundary
The public site operates without PostgreSQL, Redis, workers, scheduled jobs, live Etsy, email delivery, AI providers, social providers, billing, or external market-data providers. Health checks report this intentional mode without presenting absent providers as healthy.
Responsible disclosure
Report a suspected vulnerability privately to Support email is not configured for this environment.. Do not access another user's data, disrupt the service, or include secrets or personal data in the report.