Security at Endcap

Security is a system,
not a promise.

Endcap uses hardened sessions, CSRF protection, strict content policies, encrypted secrets and recovery bundles, protected data paths, signed updates, integrity checks, and owner-controlled hosting.

What endcap.store receives

Nothing from an installed store during normal operation. Update checks request a signed release manifest. Feedback is transmitted only after an administrator deliberately submits it.

Responsible disclosure

Send security reports to security@endcap.store. Do not include customer data.