Trust center

Security and responsible disclosure

KoalaData imports aggregate CSV reports. It does not require an extension SDK and never publishes original upload files.

Accounts

Passwords are stored as hashes, sessions use HTTP-only cookies, administrative actions are audited and seeded administrator passwords must be changed.

Uploads

File size and row limits, content checks, private storage, explicit previews and reversible import batches constrain CSV processing.

Public listings

New listings require review. External links use HTTPS validation, and verification has a narrow documented meaning.

Report a vulnerability

Use a private GitHub security advisory or email koaladata@koalastuff.net. Do not include credentials, session cookies or personal data.