Security at Nodlume

Your ideas deserve serious protection

Your projects contain product decisions and original work. Nodlume uses layered safeguards to keep that information private, intact, and available only to the people you authorize.

Identity

Server-verified sessions

Projects

Access checked per request

Payments

Card data handled by Stripe

How we protect you

Security throughout the stack

Protection is applied at sign-in, on every data request, across infrastructure, and during payment processing.

Account protection

Secure authentication

Sign-in is handled by Firebase Authentication. Sessions use a short-lived, httpOnly cookie that JavaScript cannot read, and every request that touches your data is verified on the server — not just at the edge.

Access control

Server-side authorization

Access checks run in our API layer on every mutation. Project reads and writes verify that you own the project or were invited to it; share links grant only the access they were created with.

Data protection

Encryption in transit and at rest

All traffic is served over HTTPS. Project data is stored on Google Cloud infrastructure, which encrypts data at rest and in transit between services.

Billing security

Payment data stays with Stripe

Payments are processed by Stripe, a PCI-DSS Level 1 provider. Card details go directly from your browser to Stripe; Nodlume servers never see or store your card number.

Shared responsibility

Help keep your account secure

A few careful habits make Nodlume’s built-in safeguards more effective.

  • Use a strong, unique password for your account.
  • Treat project share links as sensitive — anyone holding one can view the shared project.
  • Review who you have invited and remove collaborators who no longer need access.
  • Sign out when you finish using a shared or public computer.

Common questions

Security FAQ

Quick answers about how Nodlume protects your account, projects, and payments.

Found a potential vulnerability?

Please report it privately rather than disclosing it publicly. Include steps to reproduce the issue and the impact you observed. We will acknowledge your report, keep you informed while we investigate, and will not pursue action against good-faith research that avoids privacy violations, data destruction, and service disruption.

Submit a private report

We'd like to use Google cookies to understand how Nodlume is used and to measure our advertising. Nothing loads until you choose, and declining does not affect anything in the app.