Current foundation
- Authenticated accounts and persistent sessions through the approved authentication service.
- Separate contributor and moderator roles.
- Database row-level security as the authorization boundary.
- Private drafts and owner-scoped story access.
- Immutable versions with permission records tied to the exact version.
- Human moderation, followed by separate approval and release decisions.
- Contributor withdrawal and visible activity history.
- Private storage is required before images or audio can be accepted.
What these safeguards do not promise
They do not prevent every attack, guarantee anonymity or eliminate every human error. A public story can be copied by a reader. An alias can be linked to someone by details in the story. Security testing reduces risk but does not remove it.
Report a vulnerability
A verified security-reporting address and response process are not yet public. Do not send sensitive vulnerability details through a story submission or an invented contact form.