How access is protected
WordPress handles password hashing and authenticated sessions. Lucid checks record ownership and membership on the server. Requests use WordPress REST authentication and nonces. Uploads are limited by size, file extension and detected MIME type.
Private evidence
Original uploaded files are stored outside the public document root. Application code is maintained separately from credentials, WordPress configuration, uploads and backups.
Responsible use
Use a unique password. Do not upload broker passwords, API secrets or unnecessary personal information. Report security concerns through the contact form. This site does not claim third-party security certification.
