Legal · Security

Security

Last updated: 19 September 2026.

How MeshArc protects your account, your keys and the pages you crawl, and how to tell us when something is wrong. What we collect and why is in the privacy policy.

Reporting a vulnerability#

If you believe you have found a security problem in the app, the API, the SDKs, the MCP server or our infrastructure, write to [email protected]. Please do not open a public issue.

  • We acknowledge a report within two working days and tell you what we found and when it will be fixed.
  • Give us a reasonable time to fix the problem before you publish anything about it. We will credit you if you want to be credited.
  • Test only against accounts you own. Do not read, change or delete anyone else's data, do not run denial-of-service tests, and do not use automated scanners against the production API.
  • Findings in third parties we use (Razorpay, Cloudflare, Sentry, our hosting provider) go to them, and we will help you reach the right place.

The SDK repositories, mesharc-python and mesharc-node, each carry a SECURITY.md with the same address.

Accounts and sessions#

  • Passwords are stored as salted PBKDF2-SHA256 hashes and are never logged or emailed. A reset code lives 30 minutes.
  • A new account must verify its email address before it can act; a six-digit code lives 30 minutes.
  • A session is a random token in one HttpOnly, Secure, SameSite cookie. It lasts 30 days and ends after 14 idle days. Profile → Sessions shows every session with its time, address and browser, and ends any of them.
  • Roles gate every action: a viewer reads, a member runs, an admin issues keys, manages members and connections, and deletes projects, and the owner cannot be removed.

API keys#

  • A key is shown once at creation and stored hashed. It cannot be recovered; it can be revoked at any time under Settings → API keys.
  • A key carries the scopes it was created with (read, write, admin), optionally the projects it may see, an expiry, and a rate limit. A route outside its scopes answers 403; a project outside its list answers 404, so the key cannot confirm what it may not see.
  • The SDKs send a key only as a bearer header, only to the API base URL, and only over HTTPS. They keep nothing on disk and send no telemetry.

Tenancy and data#

  • Every document carries the workspace that owns it, and every query is scoped by it. A project id from another workspace is a 404, never a 403.
  • Destination credentials — database passwords, bucket keys, vector-store tokens — are encrypted at rest and are never returned by the API once saved.
  • Webhooks are signed; the secret can be rotated by an admin, and the verification recipe is in the developer guide.
  • Pages are kept for the retention you set on each project and deleted after it; deleting a project deletes its runs and pages.

Infrastructure#

  • All traffic to the app and the API is over TLS. Data is encrypted at rest at the hosting provider.
  • Production access is limited to the people who operate the service, over individually named accounts with multi-factor authentication. [Confirm before publishing.]
  • Error reports go to Sentry without personal data, session replays or query strings.
  • Backups are taken daily and kept for 30 days, encrypted. [Confirm before publishing.]
  • Dependencies are pinned and updated on a schedule; a critical advisory is applied out of schedule.

Crawling responsibly#

The crawler obeys robots.txt and rate limits by default and identifies itself by user agent unless a customer chooses otherwise. A site owner who wants MeshArc not to crawl their site, or wants pages removed, can write to [email protected]; see If we crawled your site.

Contact#

[email protected] for vulnerabilities · [email protected] for data requests · [email protected] for everything else.