Security
Fail closed. Verify every boundary.
Security overview · August 30, 2026
Architecture
The marketing site is a static export. Authentication is handled by Hexclave, payments by Stripe, and transactional email by Resend. Parcel API responses are served directly by a separate non-Vercel service.
Controls
- Short-lived session tokens and server-enforced project permissions.
- Scoped API keys, quota checks, rate limits, structured errors, and request IDs.
- Isolated synthetic demo storage with no production database connection.
- Privacy suppression, source verification, and release gates before public activation.
- Webhook signature verification, replay protection, and immutable administrative audit events before launch.
Report a vulnerability
Email security@parcelapis.com with affected URL, reproduction steps, and impact. Our machine-readable security contact provides the canonical policy location. Do not access data belonging to others, degrade service, or disclose a finding before remediation coordination.