FOLKBENCH / TRUST

Trust and security

Provider credentials and raw evaluation evidence do not enter public pages or browser bundles.

Last reviewed

Evaluation data flow

A controlled evaluation begins with a database run and attempt identity. High-volume process artifacts are intended for private object storage, while PostgreSQL keeps status, compact results, publication facts, audit records, and artifact manifest metadata.

Raw requests, responses, traces, logs, screenshots, and attachments are not public directory payloads. Public pages read reviewed, sanitized, versioned snapshots.

Credentials and test targets

Provider credentials must be represented by protected secret references and made available only to authorized server or worker processes. Browsers do not receive provider secrets, PostgreSQL credentials, or object-storage credentials.

Evaluation targets are subject to protocol, port, DNS, redirect, response-size, timeout, and private-network restrictions. Folkbench must not become an arbitrary network proxy.

Accounts and sessions

Where enabled, sign-in uses a Folkbench-owned session after a configured identity provider completes its flow. Session cookies are server-issued and protected; provider access tokens are not stored as application credentials. Vendor and operations roles remain separate from ordinary authentication.

Optional analytics

Browser analytics requires user consent. Before consent, Folkbench does not create a persistent analytics identifier or record events waiting to be sent. The event schema excludes search text, email, full URLs, IP addresses, session replay, and automatic click capture. If the external projection is enabled, the same fields may be sent to PostHog US Cloud.

Service-provider boundaries

Folkbench may rely on hosting, managed PostgreSQL, private object storage, identity providers, analytics, email, and—only if separately enabled—payment providers. Each provider receives only the information needed for its function and remains subject to its own terms and security responsibilities.

Report a security issue

Use the contact page and mark the subject as a Folkbench security report. Include a concise impact description and safe reproduction steps. Do not send passwords, API keys, raw private evidence, personal data, or active exploit payloads by email.