🔒 Protect your account - set up two-factor authentication. Set up now

A read-only health check of your security controls - what protection is switched on right now: IP allowlist, browser security headers, encryption at rest, and session rules. Nothing to change here; use it to confirm you are covered or spot what to turn on. Your IP: 216.73.217.11.

IP allowlist
Status: Off
Entries: 0

Enforced on every request via enforce_ip_allowlist. Admins are never locked out of their own IP when editing settings.

Configure allowlist
Response security headers

Applied on every response by _security_headers (does not overwrite values set by routes).

HeaderValue
X-Content-Type-Optionsnosniff
X-Frame-OptionsSAMEORIGIN
Referrer-Policystrict-origin-when-cross-origin
Content-Security-Policyframe-ancestors 'self'
Permissions-Policycamera=(), microphone=(), geolocation=(), payment=()
Cross-Origin-Opener-Policysame-origin
Cross-Origin-Resource-Policysame-site
Strict-Transport-Securitymax-age=31536000; includeSubDomains (HTTPS / production only)
Encryption at rest
Field encryption: Enabled (1 key)
Protected fields: 12 (PAN, Aadhaar, bank, UPI, emergency phone, 2FA secret)

On hosted plans this is set up for you. Open the encryption page to check status or encrypt older records.

Open encryption admin
Session policy
Idle timeout: disabled
Absolute lifetime: disabled
Sensitive re-auth: Off
Edit session settings