Security
Repocellar stores source code, so security decisions come first. This page describes how the product is built today.
Last updated October 6, 2026
Where your code goes
- The Chrome extension downloads repository data from GitHub, builds the backup in your browser, and uploads it directly to private object storage (Cloudflare R2) using presigned URLs that expire after two hours and are valid for one upload part each.
- Our application servers are not in the path of repository contents. They handle metadata, authorization and short-lived links.
- Backups are stored under random identifiers (no repository names) in a private bucket, encrypted at rest by the storage provider and in transit with TLS.
- Downloads use signed links that expire after ten minutes.
Verification
- Full Git Backups re-hash every Git object with SHA-1 and check that branches and tags match GitHub. Quick Backups match every file to its Git blob hash.
- Each uploaded part is checked against its MD5 by the storage service. After upload, the extension reads the whole archive back from storage and compares its SHA-256 to the one recorded before upload.
- Archive only removes a repository from GitHub after this verification, after re-checking on the server that GitHub’s branches still match the backup, and after you type the repository name.
Accounts and tokens
- Your Repocellar account and your GitHub account are separate. GitHub tokens are encrypted with AES-256-GCM, are not sent to the website, and are released only to your signed-in extension.
- The extension signs in with an authorization code and PKCE through Chrome’s identity API. Its session token is stored in extension storage that web pages and content scripts cannot read, and only a hash is stored on our side. You can revoke it under Settings → Connected devices.
- Every API request is authorized on the server and scoped to your account; plan limits (Full Git Backup, Archive, Restore, storage quota) are enforced on the server, not in the browser.
Limits
No system is perfectly secure, and these measures reduce risk rather than remove it. Keep your own copy of anything you can’t afford to lose.
Web application
- Strict Content-Security-Policy, HSTS, frame-blocking and no-sniff headers. Cross-site requests to cookie-authenticated endpoints are rejected.
- Parameterized SQL only; database tables are closed to the public database API with row-level security and no policies.
- Payment webhooks are accepted only with a valid signature and are processed exactly once.
- Security-relevant actions are written to an audit log.
Reporting a vulnerability
Email security@repocellar.com privately. Please don’t test against other people’s data. We acknowledge reports within two business days.
[YOUR LLC NAME] · [REGISTERED ADDRESS], New Mexico, USA