Reference

Security and data handling.

How authentication, query isolation, logging, and deletion work.

Security and data handling

Shibumi Forms stores form values as inert text and keeps accounts separate at the query level. Data storage describes hosted records, their location, operator access, retention, and backup behavior.

Authentication#

  • Passwordless magic links, valid for 15 minutes, consumed exactly once by an explicit confirmation click. Link scanners that prefetch URLs cannot consume them.
  • Sign-in requests pass a Cloudflare Turnstile check before any email is sent, so bots cannot drain the email budget.
  • Magic-link and session tokens are stored as SHA-256 hashes. A database copy contains no usable credentials.
  • Sessions last 24 hours, or 30 days when you choose to be remembered. Every device can be revoked from the account page.
  • Account deletion requires a fresh confirmation link sent to your email; a stolen session alone cannot destroy an account.

Submission handling#

  • Values are stored as JSON strings and rendered as inert text. Nothing submitted can execute in the dashboard.
  • CSV export escapes spreadsheet formula injection.
  • Every admin query includes the authenticated account, so one tenant can never read another's data.
  • Admin mutations require CSRF tokens and same-origin requests; the public endpoint pins CORS to your registered origin.

Logging#

Application output logs contain request IDs, route classes, status codes, and durations. Per-form request history stores timestamp, request ID, HTTP method, normalized Origin domain when supplied, response status, safe outcome code, and duration for display to the form owner. It explains rejected and failed requests to known endpoints.

Neither log contains email addresses, submission payloads, URL paths, IP addresses, user agents, tokens, cookies, or secrets. Every dashboard query for request history includes the authenticated account owner.

Deletion#

You can delete individual submissions, whole forms, or your account at any time. Deleting a submission leaves its payload-free request entry. Deleting its form or account removes that request history from the live database. Deleted records may remain in daily backup copies on the hosted persistent volume for up to 30 days.

Reporting#

Found a vulnerability or abusive form? security.txt has the contact, or write to [email protected].