Troy Pastoral AI Whisperer Edited May 28, 2026 9:58am May 28, 2026 9:58am Security Audit QA — Client Sign-OffThese are the 19 security issues we found and fixed.Protecting User Accounts A person cannot set up two-factor authentication (the extra login code) forsomeone else's account When setting up the extra login code, no data is sent to outside websites Someone cannot hack into an account by guessing the 6-digit login coderepeatedly, even using multiple internet connections A regular logged-in user cannot see other people's private folder invitationlinks When an admin views another user's account, that action is recorded securely —not visible in open server logs Blocking Malicious Content Pasting dangerous code into a knowledge base entry does nothing harmful whenother users open it AI-generated suggestions and canvas cards cannot run hidden scripts Login & Access Rules If our database has a brief outage, users from restricted countries are stillblocked — not accidentally let in Users cannot fake their location to bypass country restrictions Clicking a suspicious login link cannot redirect users to a fake external websiteafter they sign in A regular user cannot secretly upgrade their own account to admin Clearing browser data does not let a user skip the two-factor login step Background Protection Systems Attempting to manipulate the AI with trick prompts is blocked outright, not justrecorded The system detects and hides sensitive data (bank account numbers, cloud servicekeys, developer tokens) before it reaches the AI or gets stored One user flooding the system cannot accidentally lock other users out If a security event fails to log, admins are notified — nothing is silently lost File & Data Safety Uploading a deliberately broken file does not crash the system — it shows an errorand stops cleanly A one-time backup login code cannot be used twice at the same moment Backup login codes are not stored in a readable format in the database If the AI chat hits an error, no internal system details leak into the errormessage shown to users
Security Audit QA — Client Sign-Off
These are the 19 security issues we found and fixed.
Protecting User Accounts
someone else's account
repeatedly, even using multiple internet connections
links
not visible in open server logs
Blocking Malicious Content
other users open it
Login & Access Rules
blocked — not accidentally let in
after they sign in
Background Protection Systems
recorded
keys, developer tokens) before it reaches the AI or gets stored
File & Data Safety
and stops cleanly
message shown to users
cc
Red