Accounts and sessions
Argon2id passwords, randomly generated session tokens stored as hashes, expiry and per-device revocation.
Secure by design
SwiftTool combines account, permission, file, infrastructure and audit controls. No internet service can promise absolute security, so controls are reviewed and updated.
Argon2id passwords, randomly generated session tokens stored as hashes, expiry and per-device revocation.
Google OAuth with state and PKCE, plus signature verification before Telegram identity linking.
Website tables use a dedicated prefix and the VIP bridge accesses only the required record.
Docker and VIP actions pass through fixed allowlist wrappers rather than arbitrary shell access.
Do not include passwords, tokens or third-party personal data. Send a description, route and reproduction steps through Support.