Skip to content

Security

A document product, not a tenant application

SetupPasskeys delivers guides and rollout materials. It does not sign in to customer tenants, request Microsoft Graph consent, install an enterprise application, store customer administrator credentials, or make tenant configuration changes.

Paid access

All unpaid document previews are watermarked. Stripe Checkout handles card data, and the server verifies the Stripe session and one-time product metadata before unlocking downloads.

Private edit links

Buyers receive a high-entropy private edit link and a recovery code. The link is a capability credential and should not be shared. Recovery requires both the code and the purchase email, returns a uniform response, and sends the link only to the email already held for that paid order.

Admin controls

The only login is the private admin. Supabase authentication is combined with a server-side email allowlist. Service-role, Stripe, and email-provider credentials remain server-side and are never sent to the browser.

Crawler boundaries

Contact discovery is restricted to the submitted organisation's public website. It honours robots.txt, prevents private-network and cross-domain requests, ignores login pages, and considers only addresses published in public page content.

Report an issue

Please report suspected vulnerabilities privately to security@setuppasskeys.com.