EndpointOS

Security

The controls we apply on top of our infrastructure to keep your projects, keys, and customer data safe.

EndpointOS hosts production APIs for its customers. We take security as seriously as you take the customers calling those APIs. This page lists the controls actually in place today, not aspirations or marketing language.

If you believe you have discovered a vulnerability, please email support@baseframelabs.com with steps to reproduce. We will acknowledge within two business days and keep you informed as we triage and fix.

Account security

API keys and secrets

Public API protections

Webhook deliveries

Web app hardening

Infrastructure

Operational practices

Shared responsibility

You remain responsible for the API keys you distribute, the request bodies your clients send through the Service, the access mode you choose for each resource, and the security of your own client applications. We provide the controls; you decide how to use them.

Get in touch

Questions, suggestions, or a security report? Email support@baseframelabs.com or visit the contact page.

Responsible disclosure

We ask researchers to give us a reasonable window to respond before publishing details, and to avoid testing against accounts that are not their own. In return we will acknowledge your finding publicly (with your permission) and credit you in our release notes.

Security · EndpointOS | EndpointOS