Protecting account access
Passwords are salted and hashed with scrypt. API keys, session and recovery tokens are hashed at rest. Revoke keys in the workspace. Sessions use HttpOnly, SameSite=Strict cookies; production requires HTTPS. Account-changing requests enforce origin checks, and authentication endpoints use rate limits.
Keeping workspace data scoped
The public API checks ownership for keys, history, collections and results. It does not expose inherited internal admin or candidate-search routes. Exports omit password hashes, session credentials and API secrets. Closure prevents new work before deleting owned account data.
Controlling outbound requests
pageflock validates public destinations and redirects, blocks internal and metadata addresses, checks source policies and robots.txt, and bounds request size and duration. It does not accept login sessions for scraping private pages or bypass a source’s access controls.
Limits and lifecycle controls
Credits are reserved and reconciled transactionally. Account-wide rate, concurrency and collection limits apply to browser and API requests. Maintenance recovers interrupted work and prunes expired records. Collections have a seven-day result window and can be deleted after completion.
Report a security issue
Contact support with a short description, affected URL and safe reproduction steps. Do not send passwords, API keys or other people’s data. Test only accounts and systems you are authorised to use. No reward programme or response-time guarantee is implied.
Who runs pageflock.
- Legal operator
- HYVE LABS LLC
- Business address
- Sharjah Media City (Shams), Sharjah, United Arab Emirates
- Registration country
- United Arab Emirates
- Support
- abdul@hyvelabs.tech
- Privacy requests
- abdul@hyvelabs.tech
Providers, locations and transfers
pageflock is operated by HYVE LABS LLC and hosted on Google Cloud Platform (application, collection worker and PostgreSQL database in the EU region europe-west1; some Google services may process data in the United States). Payments are handled by Stripe on its hosted checkout; card details are collected and stored by Stripe, never by pageflock. Optional web, news and video search sends your query and country/language to Serper (serper.dev). Transactional email (verification and purchase receipts) is delivered through Resend. Optional, consent-based product analytics use Google Analytics. YouTube metadata requests use Google public oEmbed. These processors act under their own terms; where personal data is transferred internationally they rely on their own standard contractual clauses and safeguards.
Payment record retention
Paid and expired checkout records (checkout identifiers, amounts, credits and dates) are kept, separately from your account profile, for at least five years after the transaction to meet UAE tax and accounting obligations. Encrypted database backups are retained for up to 30 days before rotation. Account request history is pruned after 30 days and collection results after seven days.
Contact & account help