DRAFT / ELIGIBILITY PENDING — hosting evidence not yet established

Security and data handling

Access checks do not replace write safety.

Board access

Subscription trust

The browser sends a short-lived monday session token to a stateless HTTPS verifier. Only the server holds the monday client secret. The verifier accepts only HS256, checks signature, expiration, account binding, and the approved plan, and returns a minimal value-free entitlement result. Invalid, missing, stale, unknown, or unavailable state blocks product and board access.

Data minimization

The entitlement endpoint receives no board schema, operation plan, board API token, payment instrument, or item data. It stores no customer or board data and emits no raw token or subscription payload. The public site has no analytics, telemetry, cookies, or trackers.

Limitations

This is not an external security certification, penetration-test, WCAG, SOC, ISO, HIPAA, or GDPR-compliance claim. Hosting/TLS/HSTS, malware scan, processor/region, external Burp evidence, and advanced questionnaire evidence remain pending.

Report an incident

Email tafifirat@gmail.com. For suspected broader writes, credential exposure, permission bypass, or uncertain outcomes, stop the workflow and do not replay the old plan.