Auth
Sign-in federates through this app’s Better Auth to the Grok broker (Google, X). No dummy users. No SAML on this door.
Security
This page is a public posture, not a pentest report and not a certification.
Sign-in federates through this app’s Better Auth to the Grok broker (Google, X). No dummy users. No SAML on this door.
Privileged Hub routes stay authenticated. The public caller at /api/v1 is an allowlisted, rate-limited, refuse-first contract. Token completion is unavailable on this host. CORS is not *. Body cap 64 KiB. Env lamps never return secret values.
Contact inquiries are parameterized SQL. Auth sessions are per-origin Better Auth. There is no public admin console and no debug dump of other tenants. Multi-tenant Hub isolation is a Hub runtime property, not this marketing caller.
Report issues to admin@tuce.app with “Flywheel security” in the subject. We do not publish a bounty table we have not funded.
SOC 2, ISO 27001, guaranteed uptime, or neuromorphic certification.