Security that's built in, not bolted on
You're trusting us with your ideas and your users' data. Here's exactly what we do to protect them — only practices that are actually implemented today.
HTTPS everywhere
maker77, every published app on maker77.app and every connected custom domain is served over HTTPS, with certificates issued automatically.
bcrypt password hashing
Passwords — for your maker77 account and for the end users of your apps — are hashed with bcrypt. We never store or log plain-text passwords.
httpOnly session cookies
Your maker77 session is a signed JWT stored in an httpOnly, SameSite cookie (Secure in production), so page scripts can't read it.
Per-app data isolation
Every database query is scoped to a single app. One app can never read or write another app's records, users or uploads.
Isolated app origins
Published apps, builder previews and Flutter builds run on their own subdomains — never on maker77.com — so app code can't act on your maker77 account.
Collection access rules
Set each collection to public, signed-in only, owner-only or read-only from the Data tab (or m77.config.json). Rules are enforced on the server.
Project-scoped app tokens
When a user signs into an app you built, they receive a token bound to that specific project. It's useless anywhere else.
Owner-only records
Records created by a signed-in app user can only be edited or deleted by that same user. Use { mine: true } to show users only their own data.
Rate limiting
Sign-up, sign-in, password reset, forms, database writes, AI calls and uploads are rate-limited per network to slow down abuse and brute-force attempts.
Private apps & owner-only previews
Builder previews use short-lived signed links visible only to the app's owner. On paid plans you can make published apps private so only you can open them.
Shared responsibility
We secure the platform. You decide what your app collects and who can see it. A few habits go a long way:
Use auth for personal data
If your app stores anything personal, require sign-in with m77.auth and query with { mine: true }.
Don't hard-code secrets
Never paste API keys or passwords into your app's code — anything in front-end code is visible to visitors.
Make internal tools private
Building something just for you or your team? Turn on private mode in the app's Settings.
Responsible disclosure
If you believe you've found a security vulnerability in maker77, please email our contact form (topic: Security). We appreciate the work of security researchers and will treat good-faith reports seriously and respectfully.
Please include
- A description of the issue and the potential impact.
- Steps to reproduce, including URLs, request details or a proof of concept.
- Your name or handle if you'd like to be credited.
Our commitments
- We'll acknowledge your report within 3 business days.
- We'll keep you updated as we investigate and fix the issue.
- We won't pursue legal action for research done in good faith under these guidelines.
Guidelines
- Only test against accounts and apps you own, or have explicit permission to test.
- Do not access, modify or delete other users' data. Stop and report as soon as you see data that isn't yours.
- No denial-of-service, spam, social engineering or physical attacks.
- Give us reasonable time to fix the issue before disclosing it publicly.
To report an app that is being used for phishing, malware or other abuse (rather than a vulnerability in maker77 itself), use the report abuse page or the contact form.