Website security

Treat the browser as public. Keep secrets on the server.

Streamline’s website security baseline is built around a simple rule: passwords, password hashes, private API keys, database credentials, signing secrets, and other sensitive credentials must never be shipped in client-side code or placed in URLs.

01

Server-side secrets
Sensitive credentials stay in protected server or cloud configuration, not front-end JavaScript.

02

Protected authentication
Rate limiting, secure password hashing, verification steps, and secure reset flows are baseline controls.

03

No credentials in URLs
Passwords, one-time codes, and tokens should not be placed in query strings or other URL fields that can leak through history or logs.