Security posture
A read-only health check of your security controls - what protection is switched on right now: IP allowlist, browser security headers, encryption at rest, and session rules. Nothing to change here; use it to confirm you are covered or spot what to turn on. Your IP: 216.73.217.11.
IP allowlist
Status: Off
Entries: 0
Enforced on every request via enforce_ip_allowlist. Admins are never locked out of their own IP when editing settings.
Response security headers
Applied on every response by _security_headers (does not overwrite values set by routes).
| Header | Value |
|---|---|
X-Content-Type-Options | nosniff |
X-Frame-Options | SAMEORIGIN |
Referrer-Policy | strict-origin-when-cross-origin |
Content-Security-Policy | frame-ancestors 'self' |
Permissions-Policy | camera=(), microphone=(), geolocation=(), payment=() |
Cross-Origin-Opener-Policy | same-origin |
Cross-Origin-Resource-Policy | same-site |
Strict-Transport-Security | max-age=31536000; includeSubDomains (HTTPS / production only) |
Encryption at rest
Field encryption: Enabled (1 key)
Protected fields: 12 (PAN, Aadhaar, bank, UPI, emergency phone, 2FA secret)
On hosted plans this is set up for you. Open the encryption page to check status or encrypt older records.
Open encryption adminSession policy