PAGEFLOCK / SECURITY

Trust is in the details.

pageflock’s current application controls. Product safeguards, with no claim of independent certification.

Updated 17 September 2026 · Version 1.3
01

Protecting account access

Passwords are salted and hashed with scrypt. API keys, session and recovery tokens are hashed at rest. Revoke keys in the workspace. Sessions use HttpOnly, SameSite=Strict cookies; production requires HTTPS. Account-changing requests enforce origin checks, and authentication endpoints use rate limits.

02

Keeping workspace data scoped

The public API checks ownership for keys, history, collections and results. It does not expose inherited internal admin or candidate-search routes. Exports omit password hashes, session credentials and API secrets. Closure prevents new work before deleting owned account data.

03

Controlling outbound requests

pageflock validates public destinations and redirects, blocks internal and metadata addresses, checks source policies and robots.txt, and bounds request size and duration. It does not accept login sessions for scraping private pages or bypass a source’s access controls.

04

Limits and lifecycle controls

Credits are reserved and reconciled transactionally. Account-wide rate, concurrency and collection limits apply to browser and API requests. Maintenance recovers interrupted work and prunes expired records. Collections have a seven-day result window and can be deleted after completion.

05

Report a security issue

Contact support with a short description, affected URL and safe reproduction steps. Do not send passwords, API keys or other people’s data. Test only accounts and systems you are authorised to use. No reward programme or response-time guarantee is implied.

OPERATOR & CONTACT

Who runs pageflock.

Legal operator
HYVE LABS LLC
Business address
Sharjah Media City (Shams), Sharjah, United Arab Emirates
Registration country
United Arab Emirates
Privacy requests
abdul@hyvelabs.tech

Providers, locations and transfers

pageflock is operated by HYVE LABS LLC and hosted on Google Cloud Platform (application, collection worker and PostgreSQL database in the EU region europe-west1; some Google services may process data in the United States). Payments are handled by Stripe on its hosted checkout; card details are collected and stored by Stripe, never by pageflock. Optional web, news and video search sends your query and country/language to Serper (serper.dev). Transactional email (verification and purchase receipts) is delivered through Resend. Optional, consent-based product analytics use Google Analytics. YouTube metadata requests use Google public oEmbed. These processors act under their own terms; where personal data is transferred internationally they rely on their own standard contractual clauses and safeguards.

Payment record retention

Paid and expired checkout records (checkout identifiers, amounts, credits and dates) are kept, separately from your account profile, for at least five years after the transaction to meet UAE tax and accounting obligations. Encrypted database backups are retained for up to 30 days before rotation. Account request history is pruned after 30 days and collection results after seven days.

Contact & account help
YOUR PRIVACY

Choose what works for you. You can reopen these settings from the footer at any time.