Security
We take security seriously and continually improve our controls.
Account protection
Passwords are hashed with bcrypt. Session cookies are HttpOnly, Secure (when HTTPS), and SameSite=Strict.
Access control
Calendars are private by default. Public feeds are accessible only via unguessable links.
Infrastructure
We use prepared statements for all database access and enforce CSRF tokens on forms.
Vulnerability reporting
If you find a security issue, email noreply@sharemycalendar.us with details.