Security at Endcap
Security is a system,
not a promise.
Endcap uses hardened sessions, CSRF protection, strict content policies, encrypted secrets and recovery bundles, protected data paths, signed updates, integrity checks, and owner-controlled hosting.
What endcap.store receives
Nothing from an installed store during normal operation. Update checks request a signed release manifest. Feedback is transmitted only after an administrator deliberately submits it.
Responsible disclosure
Send security reports to security@endcap.store. Do not include customer data.