1. Purpose
This notice summarizes security controls on MrSoftware ET. It supplements our Terms of Use and Privacy Policy and must be acknowledged before account access.
2. Authentication
- Sessions are issued as signed JWTs stored in HTTP-only, Secure (in production) cookies — not accessible to page JavaScript
- Passwords are hashed with industry-standard algorithms; we never store plaintext passwords
- Google sign-in uses OAuth 2.0 with short-lived state tokens and verified email requirements
- Sign-in and registration endpoints are rate-limited to reduce brute-force attacks
3. Authorization
Access is enforced by role (USER, DEVELOPER, ADMIN) and per-account capability flags (upload, publish, withdraw). Admin maintenance mode may restrict sign-in to administrators only.
4. Your responsibilities
- Use a unique, strong password and enable verified email on your Google account
- Do not share session cookies, API keys, or one-time codes
- Sign out on shared devices and report lost credentials immediately
- Do not upload malware, credential dumps, or unauthorized personal data
- Review AI-generated code for vulnerabilities before deployment
5. Uploads & assets
Listing covers, profile avatars, storefront banners, and AI attachments are scanned and served through controlled routes. Only upload content you have rights to distribute. We may remove files that violate policy or pose a security risk.
6. Incident reporting
If you suspect unauthorized access, a vulnerability, or marketplace abuse, contact support@mrsoftware-et.com or use Report a problem. For critical security issues include steps to reproduce and impact assessment.
7. Updates
Security practices evolve as the platform grows. We update this notice when controls or user obligations change materially. The version shown at sign-in reflects the policy you accept.