Skip to content
Security

Security

A short summary of how we handle security today. The surface is small, and we want you to be able to read the whole page.

HTTPS by default
Every site on Blode.md is served over HTTPS.
GitHub OAuth
Sign-in runs through GitHub OAuth. We request the minimum scopes needed.
Open source
The code is public on GitHub. You can read every line.

We keep the attack surface small by design. The hosted service runs on managed infrastructure, builds happen on push, and published docs are static after deploy. Self-hosters run the same open source stack and inherit the same defaults.

For operational details on connecting repos and publishing, read the docs. For what we collect when you use the service, see the privacy policy.

Reporting an issue

Found a problem?

Email m@blode.co with steps to reproduce. Do not file a public GitHub issue for a vulnerability. This page covers the hosted platform and the open-source CLI; customer-published docs stay the publisher's responsibility. We will take a report from there.