Security
How we protect feedback and workspace access
Security is part of how we build whatsrating. This page summarizes the practical controls currently in place for workspace access, feedback-request integrity, monitoring, and data protection.
Security at a glance
- HTTPS everywhere
- Workspace-level access controls
- Audit logging
- Unique feedback-link tokens
- Error monitoring
- Responsible disclosure process
Access and workspace controls
- Email verification is required before workspace access.
- Sessions are HTTP-only cookies managed server-side.
- Workspace roles separate admin, editor, and viewer permissions.
- Team invites and join requests are reviewed through workspace access controls.
- Administrative access is restricted to authorized personnel.
Data protection
- Traffic is served over HTTPS.
- Customer data is stored using managed cloud infrastructure with access controls and encrypted transport.
- Passwords are handled by the authentication workflow and are never stored in plain text.
- Secrets are stored in environment configuration and are not shown in customer-facing settings.
- API keys are scoped to the workspace and shown only once when created.
- Sensitive operational actions are recorded in audit logs where appropriate.
Feedback-request integrity
- Email feedback links use unique tokens and reject duplicate submissions.
- Submission origin checks help prevent invalid response posts.
- Unsubscribe and suppression controls are built into the email workflow.
Monitoring, backups, and operations
- Error monitoring helps us identify and investigate reliability issues.
- Operational workflows support controlled deploys, data exports, deletion requests, suppressions, and billing events.
- Backups and managed infrastructure help maintain service reliability.
Security incidents
If we become aware of a security issue affecting customer data, we will investigate, contain the issue, and notify affected customers when appropriate.
Responsible disclosure
If you believe you found a security issue, please do not test against customer data or attempt to access another workspace. Send a concise report, affected URL, and reproduction details to hello@whatsrating.com.
Security questions
Customers with security questions may contact hello@whatsrating.com.