Kubikly

Security

These are the controls Kubikly runs today to protect your account, your files and your payments. They are described as they are implemented — nothing on this page is aspirational.

Accounts and sign-in

  • Passwords are hashed with Argon2id, a memory-hard algorithm designed to resist brute-force attacks. Kubikly never stores or sees your password in plain text.
  • Sessions are random tokens held in an HTTP-only, Secure, SameSite cookie that page scripts cannot read. Sessions expire after 30 days of inactivity; signing out ends the session, and resetting your password ends every session.
  • Sign-in attempts are rate-limited per network and per account, and password-reset and verification emails are rate-limited too.
  • Closing your account asks for your password again (for password accounts): an open browser alone is not enough.

Transport and the browser

  • Every page and API is served over HTTPS, with HTTP Strict Transport Security telling browsers never to fall back to plain HTTP.
  • A content security policy restricts where scripts, frames and connections may come from, and no page can be framed by another site.
  • Requests that change anything must come from Kubikly's own pages (same-origin checks against cross-site request forgery).
  • Standard hardening headers: no MIME sniffing, a strict referrer policy, and camera, microphone and location access disabled.

Your files

  • Uploads, renders and exports are stored privately. They are never served from a public address — only through signed links that expire, normally within an hour.
  • Uploads are identified by their actual content (their file signature), not by their name or declared type; anything that is not a recognised image or PDF is refused. Size and per-project limits apply.
  • Request bodies are size-limited, and everything a user supplies — an upload, a filename, a chat message, a certificate — is treated as data, never as instructions to the AI.

Payments and paid work

  • Credits are charged and refunded only on the server, with idempotency keys so a retry can never charge twice, and a job that fails is refunded automatically.
  • Credits are granted only when the payment provider confirms the payment through a signed notification that Kubikly verifies — not when a browser returns from checkout.
  • Kubikly stores no card numbers and no wallet keys.
  • Paid work is subject to per-hour and concurrency limits that are checked before anything is charged.

Operations

  • The application, database and file storage run on Render in Frankfurt, Germany.
  • IP addresses used for abuse prevention are stored only as keyed hashes.
  • Administrator access is limited to the admin role, and administrative actions — including opening a user's creation in the admin console — are recorded in an audit log.
  • Secrets are held in the hosting environment, never in the code, and production refuses to run without a real signing secret.

What we do not claim

Kubikly is not certified under SOC 2, ISO 27001, HIPAA or PCI DSS, and does not process card data itself. We have not commissioned an independent penetration test. If your organisation needs any of these, talk to us before relying on Kubikly for that purpose.

Reporting a vulnerability

If you believe you have found a security issue, please report it through the contact form under “Security & privacy”. Security reports are read first. Please give us reasonable time to fix an issue before disclosing it, do not access or change other people’s data, and do not run tests that degrade the service for others.

How your data is handled — providers, retention and the limits of the AI — is in the Trust Center and the Privacy Policy.

Security at Kubikly — the controls that protect your account and files · Kubikly