Security & Privacy

Your privacy matters. Chōchō is designed with security-first principles: passwordless authentication, local-only voice recordings, and minimal data collection.

Security Features

Passwordless Authentication

Magic link login - no passwords to steal or leak. Secure tokens sent to your email.

Secure Sessions

HttpOnly cookies with SameSite protection. Sessions cannot be accessed by JavaScript.

Parameterized Queries

All database queries use prepared statements to prevent SQL injection attacks.

Voice Recording Privacy

Your voice recordings stay on your device. Never uploaded without explicit consent.

Offline-First Privacy

Practice offline with downloaded content. No tracking when you are not connected.

Cloudflare Protection

DDoS protection, WAF, and encryption at rest via Cloudflare infrastructure.

OWASP Top 10 Compliance

A01

Broken Access Control

Session verification, auth checks

A02

Cryptographic Failures

Secure tokens, HTTPS only

A03

Injection

Parameterized D1 queries

A04

Insecure Design

Offline-first architecture

A05

Security Misconfiguration

Cloudflare defaults

A06

Vulnerable Components

Regular dependency audits

A07

Auth Failures

Passwordless, no credentials

A08

Data Integrity

Local-only recordings

A09

Logging Failures

Minimal data collection

A10

SSRF

No external requests

Cloudflare Platform

D1 Database

SQLite at the edge with encryption at rest. Your progress data is secure.

R2 Storage

Audio files stored with encryption. Accessed only during practice sessions.

Pages Hosting

Global CDN with DDoS protection. Fast and secure worldwide access.

ASVS Security Assessment

View our automated security assessment against OWASP Application Security Verification Standard (ASVS) 5.0.

View Assessment