Plainly, and in full. A security page that lists only strengths is marketing.
Sign in with a one-time email link or with a password — whichever you prefer. Both end in the same server-side session, and both can be protected with an authenticator app.
We generate 32 bytes of cryptographic randomness and store only its
SHA-256 hash. The raw token exists in exactly one place: the email we
just sent you.
Valid for fifteen minutes and usable once. Expired, reused or unknown tokens all return the same generic response, so the page cannot be used to discover which email addresses have accounts.
An opaque identifier in a cookie a script cannot read — and we can revoke every session everywhere, instantly.
httpOnly · Secure · SameSite. Never a token in browser storage, where
any script on the page — ours or one that got there by accident — could read it.
The session itself lives on our server, which is what makes instant revocation
possible at all.
Hashed with scrypt, never stored or logged in readable form.
Node’s standard-library scrypt — memory-hard,
N=215, a fresh 16-byte salt per account, and the cost
parameters written inside each hash so we can raise them years from now
without touching your row.
Minimum ten characters. No “one capital, one symbol” theatre —
that rule only ever produced Password1!. Passwords on the breach
lists are refused outright.
The form cannot be used to find out who has an account here.
A wrong address and a wrong password return the identical message — and an address we have never seen is still checked against a dummy hash, so both answers take the same time. Neither the wording nor the stopwatch tells an attacker anything.
Any authenticator app (TOTP). Turn it on in your account — it applies to both ways of signing in.
Billing is measured in minutes of source material, shown to you as hours.
| Rule | Value | Why |
|---|---|---|
| Billing unit | 1 minute of source | Hour-rounding punishes short uploads |
| Minimum per job | 10 minutes | Stops tiny uploads flooding the queue at no cost |
| Maximum per job | 12 hours | Matches storage and queue limits |
| Charged | on success only | A failed job costs you nothing |
| Shorts produced | does not affect price | Compute follows source length, so price should too |
| Top-up credits | never expire | Spent after your monthly allowance, so you never lose what you paid extra for |
| Layer | Control |
|---|---|
| Upload | Your file goes straight from your browser to storage with a signed, expiring URL. It never passes through our application server. |
| Download | Signed URLs with short expiry. No bucket is ever public. |
| Payments | Handled entirely by Stripe on their pages. Card details never touch our systems. |
| Transport | TLS everywhere, HSTS. |
| Database | Row-level security — a query cannot reach another account's rows even if application logic is wrong. |
| Auth gate | Fails closed. A broken verifier denies access; it never defaults to allowing it. |
| Secrets | Environment only, never committed, rotated on staff change. |
| Voice profiles | We hold none. Customer voice enrolment is not built, so there is no biometric data in your account to protect or to delete. When it is built it will store a numeric vector, never audio — and this row will say so only once that is true. |
The controls that are live today, in plain language.
Written down in advance, because the middle of an incident is the worst time to decide what to do.
Report a vulnerability: security@vigge.pro — we will not pursue anyone acting in good faith
If something here is unclear or you need it in a signed document, write to us.