← Back to PIE

Security

Security is how PIE keeps its trust promise, not an afterthought.

Signing in

PIE only supports signing in with your Google account, verified by a Cloudflare Turnstile challenge before that sign-in even begins. There is no separate PIE password to create, remember, or have stolen.

Every request checks who you are

Every action PIE takes on your behalf is checked, server-side, against your own signed-in identity - your receipts, corrections, and Insights are never reachable by anyone else's session, and PIE verifies that ownership directly rather than assuming it.

What PIE will accept from you

Every photo, PDF, or note you share with PIE is checked against an explicit allowed list and a size limit before PIE reads it, and every form you submit is checked with the same Cloudflare Turnstile challenge used at sign-in - both aimed at making sure PIE is hearing from you, and reading something real.

What PIE watches for

PIE keeps a record of security-relevant events - rejected uploads, blocked cross-site requests, failed verification attempts - so anything unusual is visible, not silent.

Reporting a concern

There is no dedicated security-disclosure address live yet - one will be listed here before PIE is generally available. If you believe you've found a real vulnerability today, please hold off on testing it against a live account.