Server-side secrets
Sensitive credentials stay in protected server or cloud configuration, not front-end JavaScript.
Website security
Treat the browser as public. Keep secrets on the server.
Streamline’s website security baseline is built around a simple rule: passwords, password hashes, private API keys, database credentials, signing secrets, and other sensitive credentials must never be shipped in client-side code or placed in URLs.
Protected authentication
Rate limiting, secure password hashing, verification steps, and secure reset flows are baseline controls.
No credentials in URLs
Passwords, one-time codes, and tokens should not be placed in query strings or other URL fields that can leak through history or logs.
