Epic Tech AI · Effective August 30, 2026
How payments, access, and media debit are locked down.
Card data never posts to our forms — Stripe Checkout only. Webhooks require Stripe-Signature. Production secrets live in host vaults, not git. Local kit is private GitHub, invite after paid Repo Access. Hosted use is entitlement-checked.
Sessions are httpOnly, SameSite=Lax cookies. The raw token is never stored. D1 keeps a SHA-256 hash and a 30-day expiry. Email codes and magic-link tokens are hashed, single-use, and expire in ten minutes. Throwaway inboxes are rejected. Owner password and GitHub client secret are Worker secrets. Vault writes cannot change the signed-in account.
No free generations. Debit happens before the Cloudflare AI run. jobId is recorded so replays do not double-charge. Prompts go through Gatekeeper deny-lists and provider safety.
Rotate leaked Stripe keys. Revoke compromised GitHub invites. Freeze entitlements for fraudulent emails. Notify affected users if personal data was exposed.
Security issues: epictechai@gmail.com with subject SECURITY.