SECURITY
Layered around account and list boundaries.
Transport and browser controls
Production traffic uses HTTPS with HSTS. Secure host-only cookies, CSRF protection, frame denial, content-type protection, referrer controls, CSP, and restricted browser permissions reduce common web risks.
Authentication
Passwords are hashed by Django. Login, registration, reset, resend, and node credential flows are throttled. Password creation and reset use the configured password validators.
Files and tenancy
Uploads are validated for supported type, size, text safety, spreadsheet structure, and unsafe archive paths. Private storage is outside the public media path, and all job operations filter by the signed-in owner.
Verification safety
The remote node has separate credentials and network identity. SMTP checks stop before DATA. Leases, row-level locks, idempotency keys, transactional credit settlement, and stale-job recovery protect concurrent work.
Scope
WorldsContact does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, or another third-party certification.