Security

Security and data handling

How Mapsource handles API keys, query data, payment information, and service access.

Keys

Keys use at least 256 random bits. Only a versioned keyed hash, prefix, and last four remain after delivery. Bearer headers are preferred.

Queries

Query text and raw request bodies are excluded from usage records, analytics, traces, and support views.

Payments

Payment details are collected in Stripe-controlled fields. Mapsource stores provider references and subscription state, not complete card numbers.

Isolation

The query engine, database, and admission store have no public host ports. Project services receive neither host GPU access nor the Docker socket.

Recovery

Billing events, entitlements, key records, and operational state are backed up, reconciled, and restored through auditable procedures.

Disclosure

Report a suspected vulnerability or unauthorized access to [email protected]. Include reproduction details without sending credentials or personal data.