Clear protection, honest boundaries, and a human contact when something needs attention.
Protecting account access
The backend uses Spring Security with hashed passwords and server-managed sessions. An HttpOnly session cookie identifies signed-in requests. State-changing browser requests require a CSRF token.
Workspace records are scoped to the signed-in account. Billing subscription events are checked using the payment provider’s webhook signature before changing plan access. These controls reduce risk; they are not a guarantee that incidents cannot happen.
Keeping your workspace safe
Use a unique password and keep access to your account email secure. Sign out on shared devices and only add information needed for coordination. Never share your password, session cookie, or payment-card details in a support message.
Email verification and password recovery use expiring, single-use email links. Password changes revoke existing sessions. Social sign-in is available through Clerk when configured. Collaborator invitations are not currently available.
Report a security concern
Email vivekgotstack@gmail.com with the subject “Security report — MeetGrid”. Include the affected page or endpoint, a brief explanation, and safe reproduction steps. Remove personal information, credentials, and session tokens from screenshots and logs.
Please avoid accessing another person’s information, disrupting the service, or publishing sensitive details while reporting an issue. This page does not establish a paid bug-bounty programme or grant permission for intrusive testing.
Scope of these statements
This page describes application controls. It does not claim independent certification, a completed external security audit, guaranteed uptime, or immunity from attacks. Hosting, transport encryption, database access, backups, and operational response also depend on the environment running the application.