Trust center
Security
DeckPilot is designed around explicit user actions, encrypted storage, rate limits, and audited administrative changes.
Authentication
User passwords are hashed. Browser sessions use HTTP-only cookies, CSRF protection, and server-side session revocation.
Production guards
Production startup rejects weak secrets, insecure cookies, SQLite, wildcard CORS, mock billing, and unreviewed demo mode unless explicitly labeled.
Integration boundary
The product does not include stealth behavior, network-routing evasion, account-risk evasion, CAPTCHA circumvention, or hidden automation. Demo mode is simulated.
Reporting
For beta deployments, report suspected vulnerabilities to the project maintainer or private repository owner. Do not include passwords, API keys, or Steam Guard codes in reports.