LivePair AI · security

Security posture, stated plainly.

What we run, how each layer is defended, who we build on — and what we don't claim. Every line below describes a mechanism in the shipping system, not an aspiration.

Cloudflare
edge network, workers, D1, R2
SOC 2 Type II · ISO 27001
Chat inference
routed via Cloudflare's edge gateway — request bodies not logged
SOC 2 · ISO 27001 provider
Live inference
dedicated realtime multimodal endpoint for session vision & voice
ISO 27001 · SOC 2 provider
PayPal
card & balance checkout
PCI DSS Level 1
Lemon Squeezy
merchant of record
PCI-compliant checkout
NOWPayments
crypto checkout
crypto settlement
layercontrolmechanism
databaseno public endpointD1 is bound to the Worker — there is no host, port, or password to attack
queriesparameterized by constructionqueries run through Drizzle ORM or static SQL — user input never becomes SQL text
passwordsscrypt 16384/16/1salted scrypt hashes; plaintext passwords never touch disk
sessionshttpOnly cookiesrolling 30-day expiry, server-side KV storage, revoked on sign-out
botstwo-layer filteredge WAF scraper block + managed challenge, then an in-worker filter before analytics
apiorigin + rate limitsmutations require a first-party Origin header; per-user and per-IP caps on sensitive endpoints
01

Architecture

The database (Cloudflare D1) has no public endpoint. It is bound to the Worker process itself — no hostname, port, or credential exists that an attacker could scan for or steal. Queries run through the ORM or as static SQL — user input never becomes query text.

Live sessions run in isolated per-session containers that get a scoped, per-session access key — one session's credentials can't open another's.

02

Identity & accounts

Passwords are salted scrypt (N=16384, r=16, p=1). Sign-in, sign-up, and OTP endpoints sit behind Cloudflare Turnstile and an auth-level rate limit. Session cookies are httpOnly with a rolling 30-day expiry; sessions can be revoked server-side.

API mutations additionally require a first-party Origin header — a foreign site can't drive authenticated requests from your browser.

03

Payments

We never see a card number. Checkout runs on PayPal, Lemon Squeezy, or NOWPayments infrastructure. Every webhook is signature-verified before it touches the ledger, grants are idempotent on the provider's reference ID so a replayed webhook can't double-credit, and a cron reconcile audits ledger invariants — if the books ever don't balance, the owner gets alerted.

04

Edge defense

All traffic rides the Cloudflare network: TLS, HSTS with a two-year max-age, and automatic DDoS absorption. At the zone, a WAF ruleset enforces the market allowlist, blocks known scraper user-agents, and issues managed challenges to automated clients — with crawl-critical files and webhooks exempted. Sensitive API routes carry an edge rate limit plus per-user limits inside the worker.

Pages ship with a strict Content-Security-Policy, frame-ancestors 'none', nosniff, and a Permissions-Policy that hands camera and microphone only to the live session itself.

05

Your data & GDPR

Analytics stores a truncated SHA-256 of IP+UA — a visit counter, not a tracking profile. Optional browser geolocation rides live observation windows only when you allow it, and sessions aren't recorded.

GDPR rights are self-serve — access, portability, erasure, and memory clearing run through Settings → Privacy & data with no support ticket: export everything we hold as JSON, clear the assistant's memory, or close the account and delete it immediately. EEA/UK/Swiss visitors get a consent bar that keeps analytics and ads storage off until accepted. Processing that leaves the EEA rides on providers' standard contractual clauses.

Model inference runs on SOC 2 / ISO 27001-certified cloud infrastructure. Agent chat routes through Cloudflare's edge gateway — request bodies aren't logged at the gateway — while live sessions run on a dedicated realtime multimodal endpoint. The full processor list is available on request.

06

Disclosure

Found something? Our disclosure contact is published at /.well-known/security.txt. We answer security reports directly.

What we don't claim: LivePair itself hasn't completed an independent third-party audit yet — that's on the roadmap, and this page will say so when it happens. The certifications above belong to the infrastructure providers we build on.