Security

Small boundaries. Clear ownership.

Trip Planner keeps authentication, ownership, entitlement, and deletion checks at the service boundaries where they can be tested and audited.

Last updated 2 August 2026

Security model

  • WorkOS authenticates the account; Convex authorizes every private read and write against the verified subject, scope, deletion state, ownership, and entitlement.
  • Widgets are read-only projections. They receive no token, internal identity, billing record, prompt, or public bearer URL.
  • Stripe is the billing authority. A redirect never grants access; only verified webhook or reconciliation truth can change entitlement.
  • Operational telemetry is content-free and excludes prompts, arguments, Trip Plan data, emails, cookies, tokens, and provider payloads.

Report a vulnerability

Send a concise report to support@tripplanner.app with the affected URL or release, reproduction steps that do not include personal data, and the impact. Do not test against another person's account, attempt to access provider systems, or include secrets or original booking documents. We respond asynchronously; the three-business-day target is not an SLA.

Security boundaries

Trip Planner is not an emergency service and does not promise a public uptime, recovery-time, or zero-data-loss guarantee. If you suspect account compromise, revoke sessions from the External Account Surface and contact support. If you suspect an urgent travel or safety issue, contact the relevant provider or emergency service.