Security

Built to be trusted

What actually stands between a buyer, a seller and a bad day on ScrollForge — described as it is, including the parts that are not built yet. The platform underneath has its own security page; this one is about the marketplace.

Last updated

01Protecting buyers

Plain English · PayGate takes your card, the marketplace records the listed price, only your account can download what you bought, and a person reads every listing before it goes live.

Card details never touch ScrollForge

Checkout is a PayGate payment form whose card fields are served by our payment partner, not by this site. This site only ever sends "buy this product" and "confirm"; your card details never reach it, and no card is stored on scrollforge.io.

The price you see is the price recorded

The marketplace reads the price from the listing inside the purchase transaction. Your browser never supplies a price, and a seller cannot buy their own product.

Downloads only for the account that bought

A download works only for a signed-in account with a completed purchase. Files are streamed server-to-server; the storage credential never reaches the browser. A full refund revokes the download.

Every listing is read by a person first

Sellers cannot self-publish. A submitted listing sits in a review queue until a Marketplace moderator publishes it or returns it with a reason.

Reviews come from verified buyers only

A review is accepted only from an account with a completed purchase of that exact product; anything else is rejected before it is stored.

A suspended seller disappears at once

Suspending a seller hides every one of their listings from the catalog and search and blocks purchases — checked at read time and again at checkout.

02Protecting sellers

Plain English · PayGate verifies you and pays you directly. Your files, listings and sales are isolated to your account at the database. Every moderation action is logged.

Verified through PayGate before you can sell

A seller profile becomes approved only after PayGate verifies you and reports that your payout account can accept charges. No form approves anyone, an outage never approves anyone, and approval is one-way.

Your money goes to your PayGate payout account

Each sale is charged directly to your PayGate payout account; ScrollForge never holds your funds. The fee split is computed server-side and a database constraint guarantees fee plus payout equals the price, to the cent.

Your files stay yours

A listing can only reference a file your own account uploaded — the marketplace verifies existence and ownership before saving, and fails closed if it cannot check.

Your data is isolated from every other account

Every marketplace table runs with row-level security forced on at the database, keyed to the account the request was authenticated as — never to anything the request itself claims.

Moderation actions are recorded

Publishing, rejecting, suspending and reinstating each write an event with the acting staff member and a comment. Moderators are a named permission; a tenant owner role is not enough.

03Files & uploads

Plain English · Every upload is checked for what it really is, not what it claims to be. Executables and scripts are refused. What we do not do is virus-scan — see section 06.

Every file a seller uploads passes these checks before it can be attached to a listing:

  • Type allow-list. Only a fixed set of image, document, text, archive and media types is accepted. SVG and HTML are excluded because a browser would execute script inside them.
  • Content-signature check. The declared type must match the file's real leading bytes. A declared type with no known signature is rejected rather than trusted.
  • Executables and scripts refused outright. Windows PE/EXE, Linux ELF, macOS Mach-O, Java class files and #! scripts are rejected regardless of the declared type — before any other rule runs.
  • Archive inspection. ZIP-family files are opened structurally: path-traversal entries, absolute paths, null bytes in names, excessive entry counts or depth, and zip-bomb expansion ratios are refused.
  • Ownership. A listing may only reference a file the seller's own account owns; the check fails closed.

These are integrity checks on the container, not a judgement about what is inside it. That judgement is the human review every listing gets, and the seller's warranty in theSeller Agreement.

04Accounts & sessions

Plain English · You sign in with your EternalEngine account through a standard OAuth flow. This site keeps your session in an encrypted, HttpOnly cookie and never hands a token to the browser. Sign out ends both sessions.

  • One account system. Sign-in is an OAuth 2.1 authorization-code flow with PKCE against EternalEngine's own auth service; scrollforge.io never sees your password.
  • Server-held session. The access token lives inside an AES-256-GCM-encrypted sf_session cookie that is HttpOnly, Secure and SameSite=Lax; page scripts cannot read it, and every API call is proxied server-side with the token attached there.
  • Return paths are sanitised. The page you are sent back to after sign-in is validated against an open-redirect check.
  • Global sign-out. "Sign out" is a same-origin form post that revokes the token, clears the session, and ends the EternalEngine app session too.
  • Silent sign-in cannot loop. The one-time silent check sets its marker cookie before it redirects, so a failed round-trip can never repeat.

Password, two-factor, passkeys and active-session management live in the EternalEngine app's account settings, which this site links to rather than re-implements.

05This website

  • Security headers on every response: a Content-Security-Policy with frame-ancestors 'none' and X-Frame-Options: DENY (no page of this site — the sign-in box included — can be shown inside another site's frame), X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin and a Permissions-Policy that disables camera, microphone and geolocation.
  • A strict Content Security Policy on every page. Scripts and styles run only if they come from this site or are one of the exact inline pieces the page was built with (each pinned by its SHA-256 hash — no 'unsafe-inline'). The only other sources allowed are the ones Stripe and Cloudflare Turnstile publish for their own widgets. An injected script is refused by your browser.
  • No caching of signed-in responses. Every /auth/*, /api/* and /account/* response is Cache-Control: no-store.
  • Same-origin images. Listing images are proxied through this site by file id; only image bodies are relayed.
  • No third-party scripts, except Stripe and Turnstile. Fonts are self-hosted, there are no analytics or advertising scripts, Stripe.js loads only on a paid listing when you are signed in and on the seller payout page, and Cloudflare Turnstile loads only inside the sign-in box when the bot check is switched on. See Cookies.
  • Every input is schema-validated at the site's own routes before it is forwarded, and the backend validates again.

06What we do not do yet

Not yet · A marketplace can imply controls it does not have. These are the ones you might reasonably assume, and would be wrong about today.

  • No antivirus or malware scanning of uploads. The scanner exists in the storage service but is switched off in every environment. Files are type-, signature- and structure-checked, then human-reviewed — not scanned.
  • No static analysis of sold software. Code is read by a reviewer, not machine-analysed.
  • No signed packages and no "verified publisher" badge. Seller identity is verified through PayGate for payments; it is not attested to buyers cryptographically.
  • No per-listing takedown button. Today a published listing is removed by suspending its seller (which hides all of that seller's listings) or by asking the seller to archive it. A single-listing action is planned.
  • No in-page report button — reports are by email, per Moderation & reporting.
  • No bug bounty payouts. We run coordinated disclosure with the response targets below, without a reward programme.
  • No certifications of the marketplace itself. PCI card-data scope sits with PayGate's payment partner, as card data never reaches us. SOC 2 and ISO 27001 are on the platform roadmap, not earned.

07Reporting a vulnerability

Plain English · Found something in the marketplace, this site, or a product sold here? Email us with reproduction steps. Good-faith research through this channel will never be met with legal action.

When a vulnerability is confirmed, the clock starts. These are the internal remediation targets our engineering process is built around, shared with the EternalEngine platform:

SeverityRemediation target
Critical24 hours
High72 hours
Medium7 days
Low30 days

Found something? · We welcome coordinated disclosure from security researchers. Emailinfo@eternalengineos.io with reproduction steps — good-faith research through this channel will never be met with legal action. For a vulnerability in a product sold on ScrollForge, tell us and the seller; we will coordinate the fix and, where needed, act on the listing.

08The platform underneath

Plain English · Honesty over badges. ScrollForge runs on the EternalEngine platform, whose own security page covers encryption, infrastructure, the secure-development gate and the compliance roadmap.

Everything above sits on the EternalEngine platform: the same auth service, the same gateway, the same database and the same engineering gate that enforces tenant isolation, parameterised queries, validated inputs and no secrets in code or logs on every change. Its security page describes those layers, the vulnerability-response commitments in writing, and the compliance status — OWASP ASVS and NIST SSDF aligned today; GDPR in progress; SOC 2 and ISO 27001 on the roadmap. We will never display a certification we have not earned.

EternalEngine security ·Data Processing Agreement ·Privacy Policy ·Your data & requests