Strong 2FA, scoped tokens, full audit log of the last 30 days, and our CSP — visible so you know what we let into your session.
full scope'self''self' 'unsafe-inline' (page-level inline scripts; CSP-nonce planned for v0.5)'self' 'unsafe-inline' fonts.googleapis.comfonts.gstatic.com'self' data: blob: *.motionsteer.studio cdn.suno.com cdn.runwayml.com cdn.lumalabs.ai klingcdn.com'self' blob: cdn.suno.com *.motionsteer.studio'self' api.motionsteer.studio api.runwayml.com api.klingai.com api.lumalabs.ai api.openai.com api.anthropic.com api.stripe.com api.elevenlabs.io'none' · no clickjacking — page cannot be iframed'self' · forms can't submit to third parties