Skip to main content
Trust & safety

What we've built to keep the Platform trustworthy

We would rather under-promise than describe features that don't exist. Here is what is live in the product today.

Account security

Argon2id password hashing, session ID rotation on login, HttpOnly/SameSite cookies, per-account and per-IP login throttling, and a device/session list you control.

Data handling

CSRF protection on every state-changing request, output escaping, and a strict content security policy. Sensitive fields are never logged in plain text.

Auditability

Security-relevant events (logins, password resets, session revocations) and privileged/financial actions are recorded server-side with request correlation IDs.

Milestone-based payments

Clients fund a milestone upfront through Stripe; funds are only released to the freelancer once the client approves the delivered work. We never see or store card details — that goes directly to Stripe.

Double-blind reviews

Reviews only become visible once both sides have submitted theirs (or a waiting period passes), so feedback reflects real experience rather than retaliation.

Moderation and disputes

Job posts, reviews and profiles are subject to our content policies, and our team can review flagged content, milestone disputes and messages when a dispute is raised.