Security posture and abuse controls.
GoLowKey keeps the public trust layer crawlable while protecting member routes with server-backed sessions, remote revocation, short-lived single-use company-email verification, and security alerts.
Private beta: $0, no payment method, 4 daily leads standard, 20 after an optional verified email or CRM connection.
- HTTPS only with a Cloudflare edge minimum of TLS 1.2 and TLS 1.3 enabled; TLS 1.0 and TLS 1.1 handshakes are rejected before reaching the application.
- HSTS, strict content security policy, frame blocking, and no public API write access from untrusted origins.
- Business-domain access only; common consumer email domains are blocked.
- Member sessions are registered server-side, shown with coarse device and region details, and can be remotely revoked. Sign-out invalidates the server session.
- Company-email verification codes expire after 10 minutes, are bound to the requesting account and session, and can be used only once.
- Verified sign-ins and remote session revocations generate account security alerts.
- Quota is enforced on the server with D1 lead claims and a KV quota ledger to survive database rebuilds: 4 daily verified leads standard, 20 after verified provider connection.
- Provider access is consent scoped. Higher daily access starts only after a verified email or CRM connection is completed and audited.
- Raw email bodies, raw contact dumps, and raw deal records are rejected by ingestion endpoints.
- Email authentication uses Microsoft 365 SPF/DKIM plus DMARC quarantine enforcement with aggregate reports routed to the GoLowKey admin mailbox.
- Passkeys, multi-factor authentication, and enterprise SSO are roadmap items and are not represented as active features today.
- Enterprise trust requests, DPA review, subprocessor review, and data-rights requests start at https://golowkey.app/trust-request.