Ownware
Security

What protects this store, and how to report a problem.

The machine-readable version of this page is /.well-known/security.txt (RFC 9116). This is the human one.

01security

Reporting a vulnerability

Email [email protected] with the product or page, the steps, and what you observed. A person reads it. Please give us a reasonable window to fix before publishing; we do not run a bounty, and we do not threaten researchers.

02security

What we do not hold

No card numbers ever touch this server: payment is handled by Lemon Squeezy as merchant of record. We hold your order email, the licence keys we issued, and the download records — nothing more.

03security

The store

Administrator sign-in requires a second factor (TOTP). Payment webhooks are verified by signature before anything is fulfilled. The origin server sits behind Cloudflare and only accepts traffic from it. The database and buyer files are backed up nightly (04:17 UTC) and copied off the server every day.

04security

The demos

Every live demo is an isolated container with sample data, reset regularly, published with a noindex header. Nothing you type into a demo reaches the store or another demo.

05security

The software you buy

Full PHP source, so you can read what runs. Each product ships with two-factor sign-in for its own admin, signed webhooks, scoped API keys (read-only keys cannot write), backups, and an audit trail — and it never phones home.

06security

Buyer portal

Sign-in is by single-use magic link to the order email. Download links are time-limited and can be re-issued from the portal.

Affiliate program
Recommend tools people own — earn 35% on every sale. 90-day tracking, instant delivery, payouts by Lemon Squeezy.
Become an affiliate →