MadePulseStudio
Security

Security is part of the product boundary.

MadePulse is designed to keep private shop data scoped to the authorized seller and to fail closed when a provider is not configured.

Private beta policy draft. Last updated: August 30, 2026.

Engineering controls

  • Database-backed sessions for connected application accounts
  • Encrypted OAuth credentials with rotation support
  • Server-resolved tenant and workspace isolation
  • Secret-safe logging and minimized provider payload handling
  • Read-only Etsy scope design
  • No live provider calls in the public demo

Public-staging boundary

The public site operates without PostgreSQL, Redis, workers, scheduled jobs, live Etsy, email delivery, AI providers, social providers, billing, or external market-data providers. Health checks report this intentional mode without presenting absent providers as healthy.

Responsible disclosure

Report a suspected vulnerability privately to Support email is not configured for this environment.. Do not access another user's data, disrupt the service, or include secrets or personal data in the report.