Trust center
Security and responsible disclosure
KoalaData imports aggregate CSV reports. It does not require an extension SDK and never publishes original upload files.
Accounts
Passwords are stored as hashes, sessions use HTTP-only cookies, administrative actions are audited and seeded administrator passwords must be changed.
Uploads
File size and row limits, content checks, private storage, explicit previews and reversible import batches constrain CSV processing.
Public listings
New listings require review. External links use HTTPS validation, and verification has a narrow documented meaning.
Report a vulnerability
Use a private GitHub security advisory or email koaladata@koalastuff.net. Do not include credentials, session cookies or personal data.
