LivePair AI · security
Security posture, stated plainly.
What we run, how each layer is defended, who we build on — and what we don't claim. Every line below describes a mechanism in the shipping system, not an aspiration.
| layer | control | mechanism |
|---|---|---|
| database | no public endpoint | D1 is bound to the Worker — there is no host, port, or password to attack |
| queries | parameterized by construction | queries run through Drizzle ORM or static SQL — user input never becomes SQL text |
| passwords | scrypt 16384/16/1 | salted scrypt hashes; plaintext passwords never touch disk |
| sessions | httpOnly cookies | rolling 30-day expiry, server-side KV storage, revoked on sign-out |
| bots | two-layer filter | edge WAF scraper block + managed challenge, then an in-worker filter before analytics |
| api | origin + rate limits | mutations require a first-party Origin header; per-user and per-IP caps on sensitive endpoints |
Architecture
The database (Cloudflare D1) has no public endpoint. It is bound to the Worker process itself — no hostname, port, or credential exists that an attacker could scan for or steal. Queries run through the ORM or as static SQL — user input never becomes query text.
Live sessions run in isolated per-session containers that get a scoped, per-session access key — one session's credentials can't open another's.
Identity & accounts
Passwords are salted scrypt (N=16384, r=16, p=1). Sign-in, sign-up, and OTP endpoints sit behind Cloudflare Turnstile and an auth-level rate limit. Session cookies are httpOnly with a rolling 30-day expiry; sessions can be revoked server-side.
API mutations additionally require a first-party Origin header — a foreign site can't drive authenticated requests from your browser.
Payments
We never see a card number. Checkout runs on PayPal, Lemon Squeezy, or NOWPayments infrastructure. Every webhook is signature-verified before it touches the ledger, grants are idempotent on the provider's reference ID so a replayed webhook can't double-credit, and a cron reconcile audits ledger invariants — if the books ever don't balance, the owner gets alerted.
Edge defense
All traffic rides the Cloudflare network: TLS, HSTS with a two-year max-age, and automatic DDoS absorption. At the zone, a WAF ruleset enforces the market allowlist, blocks known scraper user-agents, and issues managed challenges to automated clients — with crawl-critical files and webhooks exempted. Sensitive API routes carry an edge rate limit plus per-user limits inside the worker.
Pages ship with a strict Content-Security-Policy, frame-ancestors 'none', nosniff, and a Permissions-Policy that hands camera and microphone only to the live session itself.
Your data & GDPR
Analytics stores a truncated SHA-256 of IP+UA — a visit counter, not a tracking profile. Optional browser geolocation rides live observation windows only when you allow it, and sessions aren't recorded.
GDPR rights are self-serve — access, portability, erasure, and memory clearing run through Settings → Privacy & data with no support ticket: export everything we hold as JSON, clear the assistant's memory, or close the account and delete it immediately. EEA/UK/Swiss visitors get a consent bar that keeps analytics and ads storage off until accepted. Processing that leaves the EEA rides on providers' standard contractual clauses.
Model inference runs on SOC 2 / ISO 27001-certified cloud infrastructure. Agent chat routes through Cloudflare's edge gateway — request bodies aren't logged at the gateway — while live sessions run on a dedicated realtime multimodal endpoint. The full processor list is available on request.
Disclosure
Found something? Our disclosure contact is published at /.well-known/security.txt. We answer security reports directly.
What we don't claim: LivePair itself hasn't completed an independent third-party audit yet — that's on the roadmap, and this page will say so when it happens. The certifications above belong to the infrastructure providers we build on.