Skip to the page content
Nimbus Labs

Security

How your store and your buyers are protected

What we do, written so you can check it: payments on your own Stripe account, sign-in without passwords, strict rules on what your pages may run, and a refund that closes what it paid for. And, at the end, what none of it does.

Working todayOn the $29 plan, and on Pro

Your money and your account

  • Sales on your own StripeThe buyer pays on Stripe's own checkout, on your account. We never see a card number and never hold a balance of yours.
  • Prices worked out on our sideWhat a buyer is charged is read on our server from what you saved, never from anything the page sends.
  • No password to stealYou sign in with a link sent to your email. It works once, stops working after 15 minutes, and there is a limit on how often a link can be requested.
  • Passkeys, if you want themOptional: sign in with the face, fingerprint or PIN that unlocks your phone or laptop. We keep only the public half of the key, and the emailed link keeps working.
  • Team roles checked on our serverWhat an Admin, an Editor or Support may do is checked on the server for every request, not only hidden on the screen.
  • A fresh session every timeEach sign-in starts a new session, and a session the browser held before is closed.
  • Log out of all devicesOne button at the bottom of your studio closes every session you have open, everywhere.
  • An email when something important changesWhenever your Stripe account, your domain or your webhooks change, we write to your sign-in address saying what changed and when.

Your pages

  • A strict policy on what runsStore pages, on nimbuslabsai.com and on your own domain, the studio and signing in carry a Content-Security-Policy with a new nonce on every response, so text somebody typed cannot run as a script.
  • Pixels only where allowedYour Meta, Google, TikTok and Pinterest pixels load only after the visitor agrees, where the law says they must be asked.
  • Forged requests refusedEvery request that changes something must come from this site, and our cookies are HttpOnly and SameSite.
  • The usual browser protectionsHSTS, nosniff, a referrer policy, Cross-Origin-Opener-Policy, a Permissions-Policy that switches off camera, microphone and location, and no framing by other sites.
  • Emailed links go to us or to youEvery link we email points at nimbuslabsai.com or at your store's own domain, never at an address a request made up.

Files, refunds and bots

  • Downloads that expireThe download on the thank-you page works for 3 days; after that the buyer gets it again by email. Where a file is stored is never shown, and large files go through signed links that expire in minutes.
  • Files that cannot runEvery file is handed over as a download, with headers that stop a browser running anything inside it.
  • A full refund closes the doorRefund a payment in full on your Stripe account and its download stops at once, its course closes within 10 minutes, the community within 5 minutes, and its license key is revoked within about 5 minutes. A partial refund keeps access.
  • Limits that stop botsCheckouts are limited to 20 per 10 minutes per connection per store, and bookings and every form that sends an email have limits of their own, so a script cannot sit on your limited stock or your call times.
  • Signed webhooks, guarded addressesWebhooks are signed with HMAC-SHA256, and a calendar or webhook address that points into a private network is refused.
  • Email platform keys kept encryptedThe API key of your Mailchimp, Kit, beehiiv or MailerLite is encrypted before it is stored, and never shown again.
  • Reviews only from paying buyersA review can be written only for an order your own Stripe account says was paid and not refunded in full.

What this does not do

Said here so nobody relies on it for more than it does.

  • There is no two-factor sign-in, because there are no passwords. Your account is as safe as your email inbox: protect that one.
  • On a payment plan, a refund in full of the first payment closes access like any refund in full; a refund of a later payment is not detected, so take the buyer off the course, or remove their access, yourself. A refunded membership closes when its subscription is canceled in Stripe.
  • A refund cannot take back a file already saved, or a product delivered as a link to somewhere else.
  • The limits on checkouts, bookings and forms are counted in our database. If it cannot be reached, they let requests through rather than stop a buyer from paying.
  • Pages built ahead of time, such as the home page, the help center and the blog, carry a policy without a nonce. Nothing on them comes from a creator or a visitor.

Questions about security

What if I get an email about a change I did not make?

Log in, choose “Log out of all devices” at the bottom of your studio, put the setting back, and reply to that email so we can help.

Who handles a refund?

You do, in your own Stripe dashboard. What a full refund closes here happens by itself, read from Stripe.

Can I sign in with a password?

No. There is no password to set, and none kept here to be stolen. Each link we email works once, for 15 minutes.

Want this on your own store?

Take your address, connect your own Stripe account and put your first product up. $29 a month and 0% of your sales, free for the first 14 days.