Verified identity
Email-and-password accounts require email verification. Password resets use expiring, single-use links; Google sign-in remains optional.
How Numter protects account access and how to report a suspected vulnerability safely.
Email-and-password accounts require email verification. Password resets use expiring, single-use links; Google sign-in remains optional.
Numter uses HTTPS, secure cookies, restrictive browser headers, server-side authorization, and Cloudflare network protection.
Secrets remain outside source code, restricted operations require allow-listed authorization, and public pages do not expose account email addresses.
Email a clear description, affected URL, and safe reproduction steps. Do not access other users’ data, disrupt service, or publicly disclose an unresolved issue.