Security controls for accounts and assessments.
doping.ai limits page fetching, protects worker routes, separates payment handling, and stores the records that support each assessment.
Account and workspace access
Authenticated product routes require an account session. Team, profile, tracker, answer, and billing records are separated by their stored ownership relationships. Access controls must be reviewed with each material product change.
Restricted public-page fetching
Website discovery uses public HTTPS pages. The current fetch path limits redirects, response size, timeout, protocol, port, and destination. It rejects private network addresses. Discovery verifies same-domain pages before it stores them.
Protected background work
Background worker endpoints require a server secret. Durable stages store work status and support retries. Scheduled monitoring also depends on the deployment and database schedule configuration.
Separated payment processing
Self-service paid plans use a payment provider for checkout and subscription events. doping.ai uses the returned billing state to apply plan access. Full payment-card details should stay with the payment provider.
Claims we do not make
This page does not claim a security certification, formal penetration-test result, bug-bounty program, uptime guarantee, or specific encryption standard.
Report a security concern
Send the affected URL, time, steps, and possible impact to support@doping.ai. Do not include live credentials, private keys, full payment details, or unrelated personal data. Give the team a reasonable time to investigate before public disclosure.