Security & Responsible Disclosure

Security

ScopeLedger processes uploaded spreadsheets locally in your browser. File contents are not sent to the application server.

Payment and activation

Card details are entered only in Stripe-hosted Checkout. ScopeLedger creates sessions on the server and accepts a payment only after rechecking status, live or test mode, currency, amount, one-time price, metadata and line item. A success URL on its own never activates Pro access.

Webhook

The webhook processes the unchanged request body, verifies the Stripe signature within its allowed time window and then retrieves the Checkout Session directly from Stripe. Repeated fulfilment of the same session uses a stable idempotency key.

Recovery licence

The Pro entitlement contains the product, audience, issue and expiry times, plus a one-way hash of the checkout reference. It is HMAC-signed on the server and fully verified during every recovery. New pass licences expire after 7, 30 or 365 days according to the purchased weekly, monthly or annual pass; previously issued legacy entitlements keep their originally promised expiry date. The signing secret never reaches the browser.

CSV and browser data

Files are limited to 20 MB in the interface and 100,000 data rows in the parser. CSV exports neutralise leading characters that spreadsheet software could interpret as formulas. React escapes project and client text by default.

Report a security issue

Please report suspected vulnerabilities confidentially to Heaviside.Business@gmail.com Public reports containing exploit details, credentials or client data should be avoided.

Helpful information

ScopeLedger does not currently operate a bug-bounty programme. Security reports are prioritised according to risk.