Security
faibl is preparing for a bounded private beta. These are implemented controls, not a claim that an independent security assessment is complete.
Identity and account boundaries
Hosted sign-in uses Firebase. The API verifies the token and resolves a single account before returning author data. Resource queries enforce account ownership.
Provider credentials stay server-side
Database, OpenRouter, and Stripe credentials are mounted from Google Secret Manager. They are not sent to the browser or stored in source.
Author content stays out of operating logs
Application diagnostics use request IDs, route templates, safe error classes, and aggregate counters. Prompts, manuscript text, provider payloads, and credentials are excluded.
Export and deletion
Authors can export manuscript files and a complete project backup. An owned project can be permanently deleted after confirmation; account-level deletion and retention policy still require approval.