Security
Pyko takes a defense-in-depth approach. Below is a snapshot of what’s in place; the full posture document is in security review and will land before launch.
- All traffic is HTTPS in production (Cloudflare Tunnel + TLS termination).
- Passwords are hashed with bcrypt; sessions use httpOnly secure cookies with a 30-minute access window and 60-day refresh.
- We rotate refresh tokens on every use and tombstone old ones on logout.
- We never log raw passwords, payment details, or session tokens.
- If you find a vulnerability, please email [email protected]. We’ll respond within 48 hours and we won’t sue you for responsible disclosure.
(Full security overview in review. Last updated: 2026-04-26.)