Meldport

SECURITY

Security practices

How Meldport protects your account and API traffic.

Keep API keys on trusted servers, scope spend and request limits, rotate exposed keys, and retain request IDs for investigation.

Account and admin access

Customer sessions use verified identity controls. Admin endpoints require a separate email verification step before privileged access is granted.

Data handling

Credentials are stored as protected references or one-way verifiers. Public responses exclude upstream credentials, internal routes, and supply identifiers. Usage records avoid prompt and completion bodies.

Report an issue

Send security reports to security@meldport.com. Include the affected endpoint and a safe reproduction. Do not access data that is not yours. We aim to acknowledge reports within 48 hours.