SECURITY

EverCore is designed to reduce unnecessary exposure of your credentials and business data.

Security is a shared responsibility between EverCore, your device, and the third-party services you choose to connect.

Credential handling

EverCore may require API keys, personal access tokens, tracking IDs, or other connection details. These credentials should never be emailed, posted publicly, placed in screenshots, or shared with anyone who does not need them.

Local-first connection settings

Where supported, EverCore is designed to keep user-provided connection information on the user’s device rather than sending it to a general EverCore account database.

GitHub access

Use a fine-grained GitHub personal access token with only the repository access and permissions required for publishing. Avoid broad account-wide permissions when they are not needed. Revoke and replace a token immediately if you believe it has been exposed.

AI provider keys

Use a dedicated API key when possible, review provider usage regularly, set spending limits or alerts when available, and revoke keys that are no longer in use.

Cloudflare-powered click tracking

EverCore’s click-tracking workflow is designed to receive limited routing and attribution information, record the product click, and redirect the visitor to the affiliate destination. It should not be used to collect unnecessary sensitive information.

App and device protection

Keep iOS updated, use a strong device passcode, enable Face ID or Touch ID, protect access to your email and GitHub accounts, and do not use EverCore on a device you do not control.

Third-party security

Apple, GitHub, Amazon, AI providers, and Cloudflare maintain their own security controls. EverCore cannot guarantee or control the security of those services.

Incident reporting

Report suspected security issues to 7vncustoms@gmail.com. Do not include passwords, API keys, or access tokens in the message.

Responsible disclosure

Security researchers should provide enough detail to reproduce the issue, avoid accessing other users’ information, avoid disrupting the service, and allow reasonable time for investigation before public disclosure.