citizen.stream

citizen.stream

Security

Version 2026-10-03

Where it runs

Dedicated servers in the European Union. No published service ports; only the web proxy faces the internet. The radio engine's control interface is internal.

Accounts

  • Passwords: minimum 12 characters, stored as scrypt hashes.
  • Sessions: HTTP-only, Secure, SameSite cookies bound to a server-side record; sign-out revokes them.
  • Sign-in and public forms are rate limited. Every state-changing request carries a CSRF token.
  • Roles: owner, editor, sales, viewer. Every action is written to an audit trail.

Isolation

Each organisation's places, audio, team and operator conversations are scoped to that organisation in every query, and the test suite proves one organisation cannot read another's.

In the browser

A strict content security policy with per-request nonces, no third-party scripts, fonts or trackers, HSTS, and framing denied.

Secrets and data

Service credentials are encrypted at rest with AES-256-GCM. Uploaded audio is checked to be audio before processing. Webhooks authenticate with a per-place secret and can only fetch from public HTTPS addresses.

The operator

The assistant acts only through a fixed list of tools, only inside the organisation of the person talking to it, and cannot run anything destructive without a human approving it.

Reporting a problem

Email security@citizen.stream. See security.txt. We acknowledge within two working days and do not pursue good-faith research.