Skip to content

Security

Security you can verify

We'd rather show you the controls than just claim them. Here's what's protecting your account today, and what we're still building.

Live

Email-verified sign-in

No bot can be created or run until you've verified your email — enforced both in the app and at the database layer.

Live

Per-user database rules

Every bot record is scoped to its owner. Database rules block reading, editing, or running anyone else's bot.

Live

Code safety gate

Before a bot runs, its code is parsed and checked for filesystem access, shell commands, dynamic imports, and sandbox escapes. Dangerous code is blocked.

Live

Hardened HTTP headers

A strict Content-Security-Policy, HSTS (HTTPS-only), clickjacking protection, and MIME-sniffing protection ship on every response.

Live

Re-authentication for sensitive actions

Changing your password or deleting your account requires re-entering your credentials, so a walked-away session can't do damage.

Live

Encrypted in transit

All traffic to and from Clockwise is served over HTTPS with automatic certificate management.

What we're still building (and won't pretend otherwise)

During beta, bot tokens are stored as part of your script and are not yet encrypted at rest, and bots are isolated by process rather than fully sandboxed from one another. We're actively working on encryption-at-rest and per-bot isolation before opening to the wider public. Rotate your token anytime in the Discord Developer Portal if you have any concern.

Found a vulnerability? Please report it privately to support@clockwise.cv — we appreciate responsible disclosure.