Skip to content
Preliminary draft — not attorney-approved

These pages are first-pass language and are not legal advice. They are written by the team to be honest and easy to read; consult your own counsel before relying on them in a contract. We'll mark the date each section was last revised at the top of the page.

Preliminary draft · Security

Security

A candid description of what’s enforced today, what isn’t, and how to report an issue.

Last updated 2026-08-17 — language is a working draft, not legal advice.

Transport

HTTPS, HSTS, and CSP

Every served page is over HTTPS. The platform publishes HSTS and a strict Content Security Policy with a per-request nonce. Tollcast doesn't expose a subframe surface, so the response carries a CSP of frame-ancestors 'none'.

Auth & sessions

Sessions, rate limits, and CSRF

Sessions are 14-day rolling, refreshed every 24h of activity. better-auth handles the cookie, the same-origin check, and the CSRF token on every POST. We add a per-IP rate-limit on forgotten-password and reset-password endpoints so a stranger can't enumerate accounts or reset at scale.

Honest gaps

What isn’t enforced

Tollcast has no formal SOC2 audit yet. There is no WAF today — the protection we lean on is HTTPS, CSP, and rate limits. The audit log is the Polsia platform analytics; we don't run a separate SIEM.

Our audit posture is whatever the platform swallows — a sliding window of platform analytics events, no third-party tooling. We disclose a material incident the same week it'd be detected; what counts as material is decided with our counsel. If a regulated workload needs more, write to us before signing up.

Reporting

How to report a vulnerability

Found a security issue? Email tollcast@polsia.app with the reproduction steps. We aim to respond within two business days and to acknowledge public credit for the report once the fix ships.