Security & Safety
Training data is personal, and body measurements, photographs and injury notes are sensitive. This page describes what we actually do — in enough detail that you can hold us to it.
Signed sessions
Your session cookie carries a HMAC-SHA256 signature. The server recompiles it on every request and compares in constant time, so a cookie cannot be forged or edited to impersonate another account. The cookie is readable by our own JavaScript by design — it restores your session when iOS clears local storage — which is why the signature, not secrecy, is what protects it.
Passwords are never stored
Passwords are hashed with scrypt and a random 16-byte salt per account, and verified in constant time. We cannot read your password, and neither could anyone who obtained the database.
Authorisation on every request
Identity comes from the signed cookie, never from an id in the URL or request body. Every route that touches a client record re-checks that the caller owns it — following both directions of the coach–athlete link, so a half-linked account is neither locked out nor let in.
Invite-only coach registration
A coach account cannot be created without an invite code we issued. The code is claimed inside the same database transaction that creates the account, so it can never be used twice, and it can be revoked before use.
Rate limiting and origin checks
Sign-in, sign-up, password reset, one-time codes and the public waiting list are rate limited per address, and state-changing requests are checked against their origin. Brute force and cross-site request forgery both run into a wall.
Hardened browser headers
A strict Content-Security-Policy limits what the page may load. HSTS forces HTTPS for two years. Framing is denied outright, MIME sniffing is off, and referrers are trimmed when leaving the site.
Parameterised queries
Every database query is parameterised — values are sent separately from the statement, never pasted into it. SQL injection has nothing to attach to.
Daily backups
The database is backed up every night. Backups are retained for 30 days and then overwritten. They are a disaster-recovery measure, not an archive — see the deletion note below.
What we do not claim
We use third parties
Hosting, storage, email and AI features run on established third-party services we do not own. The Privacy Policy sets out what each kind of provider receives.
We are not an archive
Photographs, video and voice notes attached to a session are deleted permanently 30 days afterwards. Backups are overwritten after 30 days. Save anything you need to keep.
No absolute guarantee
No system is perfectly secure and we will not pretend otherwise. We have not been independently audited or certified. What we can promise is that everything on this page is true of the code as written.
What you can do
- Use a password you use nowhere else, and never share it.
- Sign out on any device that is not yours.
- Coaches: a passkey is a key. Send it to the athlete it belongs to and nobody else.
- Athletes: record only what your coaching actually needs. You can delete a photograph or recording of yourself at any time.
- Tell us immediately if you think someone else has reached your account.
Reporting a vulnerability
If you find a weakness, tell us before you tell anyone else and we will not come after you for it. Send what you found, and enough detail to reproduce it, to the address below. We aim to acknowledge within 3 business days and to keep you informed until it is closed.
Please do not run automated scanners against the live service, access or modify an account that is not yours, or read another person’s training data. Stop at the point where you have proved the issue exists.
info@monolith.coach