Security
Last updated: 17 July 2026
A document product, not a tenant application
SetupPasskeys delivers guides and rollout materials. It does not sign in to customer tenants, request Microsoft Graph consent, install an enterprise application, store customer administrator credentials, or make tenant configuration changes.
Paid access
All unpaid document previews are watermarked. Stripe Checkout handles card data, and the server verifies the Stripe session and one-time product metadata before unlocking downloads.
Private edit links
Buyers receive a high-entropy private edit link and a recovery code. The link is a capability credential and should not be shared. Recovery requires both the code and the purchase email, returns a uniform response, and sends the link only to the email already held for that paid order.
Admin controls
The only login is the private admin. Supabase authentication is combined with a server-side email allowlist. Service-role, Stripe, and email-provider credentials remain server-side and are never sent to the browser.
Crawler boundaries
Contact discovery is restricted to the submitted organisation's public website. It honours
robots.txt, prevents private-network and cross-domain requests, ignores login
pages, and considers only addresses published in public page content.
Report an issue
Please report suspected vulnerabilities privately to security@setuppasskeys.com.