Security
What we do to keep your account and your sites' data safe.
Where it runs
UsherStats runs on Cloudflare's network: Workers for the code, D1 for accounts, Durable Objects for each site's own store, Analytics Engine and R2 for traffic data. Every connection uses TLS.
Keeping customers apart
- Each site has its own store; no store answers for another site.
- Every request is checked against the account and sites it belongs to on the server. An id in a request is never trusted on its own, and tests run a second customer beside the first to prove neither can read the other.
Accounts and tokens
- Passwords are stored only as slow, salted hashes, and checked against known breached passwords.
- Two-factor sign-in with an authenticator app.
- API tokens are shown once, stored hashed, and can be limited by scope, by site and by expiry.
- Roles for team members (owner, admin, member, viewer), and an audit log of changes.
Your credentials
Search Console and Bing credentials you connect are encrypted before they are stored, and used only to fetch your own data.
What we do not keep
Visitors' IP addresses and full browser strings are used while a request is handled, to classify it, and not stored with your analytics. Analytics sets no cookies on your visitors.
Reporting a problem
Write to ops@usherstats.com. We will confirm receipt, keep you informed, and credit you if you wish.