What we've built to keep the Platform trustworthy
We would rather under-promise than describe features that don't exist. Here is what is live in the product today.
Account security
Argon2id password hashing, session ID rotation on login, HttpOnly/SameSite cookies, per-account and per-IP login throttling, and a device/session list you control.
Data handling
CSRF protection on every state-changing request, output escaping, and a strict content security policy. Sensitive fields are never logged in plain text.
Auditability
Security-relevant events (logins, password resets, session revocations) and privileged/financial actions are recorded server-side with request correlation IDs.
Milestone-based payments
Clients fund a milestone upfront through Stripe; funds are only released to the freelancer once the client approves the delivered work. We never see or store card details — that goes directly to Stripe.
Double-blind reviews
Reviews only become visible once both sides have submitted theirs (or a waiting period passes), so feedback reflects real experience rather than retaliation.
Moderation and disputes
Job posts, reviews and profiles are subject to our content policies, and our team can review flagged content, milestone disputes and messages when a dispute is raised.