Security

faibl is preparing for a bounded private beta. These are implemented controls, not a claim that an independent security assessment is complete.

Identity and account boundaries

Hosted sign-in uses Firebase. The API verifies the token and resolves a single account before returning author data. Resource queries enforce account ownership.

Provider credentials stay server-side

Database, OpenRouter, and Stripe credentials are mounted from Google Secret Manager. They are not sent to the browser or stored in source.

Author content stays out of operating logs

Application diagnostics use request IDs, route templates, safe error classes, and aggregate counters. Prompts, manuscript text, provider payloads, and credentials are excluded.

Export and deletion

Authors can export manuscript files and a complete project backup. An owned project can be permanently deleted after confirmation; account-level deletion and retention policy still require approval.