Security
Simple boundaries, careful handling.
StickDrop authenticates dashboard users and limits project management by group. Public access is encrypted with HTTPS.
Uploaded content is handled as untrusted static files. StickTools does not execute it server-side. Archive paths and file types are validated, deployments activate atomically, and dashboard and project cookies are scoped to their exact hosts.
A project password gate is useful for controlled sharing, but authorized viewers still receive the content in their browsers. It should not be treated as a protected-data vault.
Report a vulnerability
The operator has not yet published a security reporting address. The machine-readable security contact remains unavailable until a real contact is configured.