Security

Security that's built in, not bolted on

You're trusting us with your ideas and your users' data. Here's exactly what we do to protect them — only practices that are actually implemented today.

HTTPS everywhere

maker77, every published app on maker77.app and every connected custom domain is served over HTTPS, with certificates issued automatically.

bcrypt password hashing

Passwords — for your maker77 account and for the end users of your apps — are hashed with bcrypt. We never store or log plain-text passwords.

httpOnly session cookies

Your maker77 session is a signed JWT stored in an httpOnly, SameSite cookie (Secure in production), so page scripts can't read it.

Per-app data isolation

Every database query is scoped to a single app. One app can never read or write another app's records, users or uploads.

Isolated app origins

Published apps, builder previews and Flutter builds run on their own subdomains — never on maker77.com — so app code can't act on your maker77 account.

Collection access rules

Set each collection to public, signed-in only, owner-only or read-only from the Data tab (or m77.config.json). Rules are enforced on the server.

Project-scoped app tokens

When a user signs into an app you built, they receive a token bound to that specific project. It's useless anywhere else.

Owner-only records

Records created by a signed-in app user can only be edited or deleted by that same user. Use { mine: true } to show users only their own data.

Rate limiting

Sign-up, sign-in, password reset, forms, database writes, AI calls and uploads are rate-limited per network to slow down abuse and brute-force attempts.

Private apps & owner-only previews

Builder previews use short-lived signed links visible only to the app's owner. On paid plans you can make published apps private so only you can open them.

Shared responsibility

We secure the platform. You decide what your app collects and who can see it. A few habits go a long way:

Use auth for personal data

If your app stores anything personal, require sign-in with m77.auth and query with { mine: true }.

Don't hard-code secrets

Never paste API keys or passwords into your app's code — anything in front-end code is visible to visitors.

Make internal tools private

Building something just for you or your team? Turn on private mode in the app's Settings.

Responsible disclosure

If you believe you've found a security vulnerability in maker77, please email our contact form (topic: Security). We appreciate the work of security researchers and will treat good-faith reports seriously and respectfully.

Please include

  • A description of the issue and the potential impact.
  • Steps to reproduce, including URLs, request details or a proof of concept.
  • Your name or handle if you'd like to be credited.

Our commitments

  • We'll acknowledge your report within 3 business days.
  • We'll keep you updated as we investigate and fix the issue.
  • We won't pursue legal action for research done in good faith under these guidelines.

Guidelines

  • Only test against accounts and apps you own, or have explicit permission to test.
  • Do not access, modify or delete other users' data. Stop and report as soon as you see data that isn't yours.
  • No denial-of-service, spam, social engineering or physical attacks.
  • Give us reasonable time to fix the issue before disclosing it publicly.

To report an app that is being used for phishing, malware or other abuse (rather than a vulnerability in maker77 itself), use the report abuse page or the contact form.