Evaluation data flow
A controlled evaluation begins with a database run and attempt identity. High-volume process artifacts are intended for private object storage, while PostgreSQL keeps status, compact results, publication facts, audit records, and artifact manifest metadata.
Raw requests, responses, traces, logs, screenshots, and attachments are not public directory payloads. Public pages read reviewed, sanitized, versioned snapshots.
Credentials and test targets
Provider credentials must be represented by protected secret references and made available only to authorized server or worker processes. Browsers do not receive provider secrets, PostgreSQL credentials, or object-storage credentials.
Evaluation targets are subject to protocol, port, DNS, redirect, response-size, timeout, and private-network restrictions. Folkbench must not become an arbitrary network proxy.
Accounts and sessions
Where enabled, sign-in uses a Folkbench-owned session after a configured identity provider completes its flow. Session cookies are server-issued and protected; provider access tokens are not stored as application credentials. Vendor and operations roles remain separate from ordinary authentication.
Optional analytics
Browser analytics requires user consent. Before consent, Folkbench does not create a persistent analytics identifier or record events waiting to be sent. The event schema excludes search text, email, full URLs, IP addresses, session replay, and automatic click capture. If the external projection is enabled, the same fields may be sent to PostHog US Cloud.
Service-provider boundaries
Folkbench may rely on hosting, managed PostgreSQL, private object storage, identity providers, analytics, email, and—only if separately enabled—payment providers. Each provider receives only the information needed for its function and remains subject to its own terms and security responsibilities.
Report a security issue
Use the contact page and mark the subject as a Folkbench security report. Include a concise impact description and safe reproduction steps. Do not send passwords, API keys, raw private evidence, personal data, or active exploit payloads by email.