Security

Version 1.0 · Effective 26 July 2026

The most useful security property of Choreo is architectural: with no account, there is no server-side copy of your work to breach. Everything below concerns the optional hosted parts.

1In transit and at rest

All traffic is served over HTTPS. Synced documents and assets are stored on Cloudflare infrastructure, encrypted at rest, in a private bucket that only the service can read.

2Sign-in

Authentication is delegated to Google, so we never see or store a password. Your session is a signed token held in your browser for 90 days; signing out discards it.

3Access

File contents are addressed per account, and requests are checked against the signed-in owner. Administrative access exists only to operate the service and to publish gallery templates.

4Reporting a vulnerability

Write to [email protected] with enough detail to reproduce the issue. Please give us a reasonable window to fix it before publishing, and avoid accessing other people's data while testing. We will confirm receipt and keep you posted on the fix.

Choreo is operated by Anas Bel Madani. Reach us at [email protected].