shipboard.lol

Security

Last updated:

Short version: our GitHub App can only read, we store metadata about your commits and never your code, and every claim below is backed by an automated test.

What we can access

  • Your repos: the GitHub App asks for read-only access to contents and metadata. It can't push, open issues or change settings. We read commit metadata and never store file contents or commit messages.
  • Your account: signing in with GitHub gives us your user ID, username, avatar and email address. We don't get your GitHub password or a token to act as you.
  • Payments: Stripe handles card details. We never see your card number.

How it's protected

  • Every database table has row-level security. Visitors can read only public board data, and owners can edit only their own project's text.
  • GitHub and Stripe webhooks are checked against their signatures before we act.
  • Follower email addresses are never public and never shown to owners. Unsubscribe links are signed and delete your address right away.
  • Secrets live only in our hosting provider's settings, never in the code. Admin pages check every request against a fixed list.
  • Pages can't be framed by other sites, except the widget owners embed on purpose.

Last review

We last reviewed security on 2026-10-01. This is an internal review by our own team, not an independent audit. See also our privacy page.

Report a problem

Email hello@shipboard.lol. We'll reply within 3 working days. Please test only against your own account and data, and give us a chance to fix the issue before you share it. We won't take legal action over good-faith research that follows these rules.