Back homeSecurity
This page describes what Swazy actually does today — not plans. If something here stops being true, this page changes.
Every page, upload and payment step is served over an encrypted connection only. Browsers are told to refuse an unencrypted version of Swazy outright.
Uploaded files never sit in a public folder. A buyer's download link is signed for that buyer, checked against what they actually bought, and stops working shortly after it is created.
Customers, sales, leads and progress are separated per creator at the database level. One creator cannot read another creator's records, and a visitor can only read what a published page shows.
Card details are entered on Stripe's own hosted checkout. Swazy never sees or stores a card number, and payment confirmations are accepted only when Stripe's signature proves they are genuine.
Public actions — claiming an offer, joining a list, restoring access — are rate limited per visitor with honest messages when a limit is hit. The page cannot be embedded in someone else's site, and only the services Swazy actually uses are allowed to run on it.
Report it privately to security@swazyy.com and give us a reasonable window to fix it before sharing publicly. Please don't test against real creator pages, real buyers or real payments. Machine-readable details live at /.well-known/security.txt.