Last updated · 31 August 2026
Security
How Quadrantcode protects account and practice data.
Controls
Passwordless sign-in uses short-lived, single-use tokens; sessions are HTTP-only, secure in production, revocable, and rotated. Sensitive endpoints use distributed rate limits and validated inputs.
Data boundaries
Secrets stay server-side, database access is scoped by the authenticated user, uploads are size/type checked, and arbitrary code is sent only to the configured isolated execution provider with explicit limits.
Report a vulnerability
Please avoid accessing other users’ data. Send a concise report to vikramyadav6704@gmail.co.