SECURITY
Security practices
How Meldport protects your account and API traffic.
Keep API keys on trusted servers, scope spend and request limits, rotate exposed keys, and retain request IDs for investigation.
Account and admin access
Customer sessions use verified identity controls. Admin endpoints require a separate email verification step before privileged access is granted.
Data handling
Credentials are stored as protected references or one-way verifiers. Public responses exclude upstream credentials, internal routes, and supply identifiers. Usage records avoid prompt and completion bodies.
Report an issue
Send security reports to security@meldport.com. Include the affected endpoint and a safe reproduction. Do not access data that is not yours. We aim to acknowledge reports within 48 hours.