Troy Pastoral AI Whisperer Edited May 28, 2026 9:58am May 28, 2026 9:58am Security Audit QA — Client Sign-OffThese are the 19 security issues we found and fixed.Protecting User AccountsA person cannot set up two-factor authentication (the extra login code) forsomeone else's accountWhen setting up the extra login code, no data is sent to outside websitesSomeone cannot hack into an account by guessing the 6-digit login coderepeatedly, even using multiple internet connectionsA regular logged-in user cannot see other people's private folder invitationlinksWhen an admin views another user's account, that action is recorded securely —not visible in open server logsBlocking Malicious ContentPasting dangerous code into a knowledge base entry does nothing harmful whenother users open itAI-generated suggestions and canvas cards cannot run hidden scriptsLogin & Access RulesIf our database has a brief outage, users from restricted countries are stillblocked — not accidentally let inUsers cannot fake their location to bypass country restrictionsClicking a suspicious login link cannot redirect users to a fake external websiteafter they sign inA regular user cannot secretly upgrade their own account to adminClearing browser data does not let a user skip the two-factor login stepBackground Protection SystemsAttempting to manipulate the AI with trick prompts is blocked outright, not justrecordedThe system detects and hides sensitive data (bank account numbers, cloud servicekeys, developer tokens) before it reaches the AI or gets storedOne user flooding the system cannot accidentally lock other users outIf a security event fails to log, admins are notified — nothing is silently lostFile & Data SafetyUploading a deliberately broken file does not crash the system — it shows an errorand stops cleanlyA one-time backup login code cannot be used twice at the same momentBackup login codes are not stored in a readable format in the databaseIf the AI chat hits an error, no internal system details leak into the errormessage shown to users
Security Audit QA — Client Sign-Off
These are the 19 security issues we found and fixed.
Protecting User Accounts
someone else's account
repeatedly, even using multiple internet connections
links
not visible in open server logs
Blocking Malicious Content
other users open it
Login & Access Rules
blocked — not accidentally let in
after they sign in
Background Protection Systems
recorded
keys, developer tokens) before it reaches the AI or gets stored
File & Data Safety
and stops cleanly
message shown to users