StarlineSales runs Live Search and AI Research through your own connected
search and AI provider keys — we never see a query cost or a token bill —
and encrypts every credential it stores on your behalf.
Your data is yours, exportable, deletable
Companies, prospects, campaigns, research and search history are stored on the server so Live Search can work at all — a real search costs real money and cannot be discovered twice from a browser cache. Nothing here is sold, shared, or used to train anything. It is yours: exportable and deletable on request.
Credentials encrypted at rest
SMTP passwords and API keys — including your own search provider and AI provider keys — are encrypted with AES-256-GCM and stored outside the web root. They are never sent to the browser and never appear in a page, a log or an error message.
Passwords are hashed, never stored
Account passwords are hashed with bcrypt. Nobody — including us — can read them back. A password issued by an administrator must be changed at first sign-in.
HTTPS everywhere, enforced
The site is HTTPS-only with HSTS set for a year. Session cookies are Secure, HttpOnly and SameSite=Lax, and the session identifier is regenerated on sign-in.
A strict content security policy
Scripts and styles load from this origin only. No third-party analytics, no tag managers, no advertising pixels, no external fonts. There is no inline script anywhere in the product.
Everything security-relevant is logged
Sign-ins, failures, sign-outs and every account change are recorded with the actor, the subject, the time and the address. Administrators can see active sessions and end any of them.
Roles that actually restrict
Permissions are enforced on the server before a route is dispatched, not hidden in the interface. A beta user requesting an admin URL directly is refused.
Sign-in attempts are limited
Failed attempts are counted per email address and per network address, in the database — so discarding a cookie does not reset the count.
Verification and reset links expire, and work once
An email-verification link is valid for 24 hours; a password-reset link for one hour, and is deleted the moment it is used. Neither can be replayed.
What we have not done
A security page listing only strengths is not a security page. These are
the gaps we know about.
No two-factor authentication
Accounts are protected by a password alone. 2FA is planned and not built.
No independent security audit
Nobody outside the team has reviewed this code. We are not going to imply otherwise.
A central database now exists
Live Search moved company and prospect data to the server (see "Your data is yours" above) so search results, provenance and AI research could persist. That is a real change of shape from an earlier, browser-only version of this page — worth stating plainly rather than leaving the old claim standing.
Found something? Email
security@starlinecart.com
with what you found and how to reproduce it. We will acknowledge within
two working days, and we will not take action against anyone who reports
a problem in good faith.