What's actually implemented today, stated plainly — including the parts that aren't built yet. We'd rather tell you "not yet" than describe something we can't back up.
The NetL website at netl.online is served over HTTPS/TLS. The desktop application's connections to our backend for account sign-in and session checks are made over encrypted connections, not plain HTTP.
Account-related requests between the NetL application and our backend travel over encrypted connections. We have not published a detailed breakdown of our backend architecture or API hardening measures beyond this — we'd rather leave this section short than describe specifics we can't stand behind publicly.
We have not published specific rate-limiting configuration or thresholds, consistent with standard practice of not detailing anti-abuse mechanisms that could help someone circumvent them. If you believe you've encountered abusive automated traffic involving NetL, let us know via Section 12.
Application secrets and service credentials are not embedded in the NetL application binary distributed to users, and are not present in the website's public source. Beyond that general practice, we do not publish detailed configuration-management information.
Passwords are hashed, not stored in reversible form, as described in Section 2. Beyond password hashing, we have not published a separate, formal statement on database-level encryption-at-rest configuration.
We do not currently run or publish a formal, ongoing dependency/vulnerability scanning program. This is accurately described as not currently implemented, and is a candidate for future improvement rather than an existing control.
The session and device-activity logs described in our Privacy Policy are access-restricted and used only for the account-security and support purposes stated there — not for advertising, and not shared with third parties beyond what's disclosed in that policy.
We have not published specific backup or disaster-recovery details for our account database. This section is intentionally left at "not currently published" rather than describing a formal backup program we haven't documented.
We do not currently operate a formal, published uptime-monitoring or alerting program — see our Status page for more on how we handle this today.
We do not yet have a formally published, staffed incident-response plan. If a security incident occurs that we reasonably believe affects your personal data, we will notify affected users by email, consistent with the data breach notification commitment in our Privacy Policy.
If you discover a security vulnerability in NetL, our website, or our infrastructure, we want to know. Email support@netl.online with [SECURITY] in the subject line, including steps to reproduce and any relevant detail. Please give us reasonable time to investigate and address the issue before any public disclosure. We do not currently operate a paid bug bounty program.
Checksums (e.g. SHA-256) are not currently published alongside each release. Until code signing and published checksums are in place, only download NetL from netl.online or our official GitHub Releases page — treat any other source as unofficial. We recommend scanning any installer with your own antivirus software before running it, as good general practice for any downloaded application.
See the "Who we share it with" section of our Privacy Policy for the current list of infrastructure and service providers with access to account data.