Security
Updated 14 Sep 2026
Auth model
First-party authentication on getcitebrief.com only (email/password, magic link, Google). Optional domains such as citebrief.xyz must 301 redirect and must not set auth cookies. Production rejects stub and dev-admin internal secrets.
Data storage
Application data lives in Cloudflare D1. Report HTML and PDFs live in R2. Better Auth rate-limit and session cache may use KV. Transport is HTTPS with HSTS, frame denial, and a content security policy.
Payments, email, AI
Cards are handled by Dodo Payments. We do not store card numbers. Transactional email is Cloudflare Email Service. Model calls go through Cloudflare AI Gateway rather than raw provider keys in product code. Live engines do not silently stub-succeed.
Reports and access
Client links are unguessable tokens, noindex, 90-day expiry, and revocable in the report viewer. Internal admin impersonation, webhook replay, billing, invites, and report sends write audit logs. Rate limits apply to sign-in, runs, sends, invites, public tokens, and admin routes.
Incidents
Report suspected incidents to support@getcitebrief.com. We will acknowledge and follow up with affected workspace owners when required.
Contact: support@getcitebrief.com