Security
Security you can actually verify
No jargon and no badges we haven’t earned — just a plain account of how growthh keeps your account and your apps safe.
Every request is served over TLS (Let’s Encrypt). We send HSTS with preload, and growthh.dev sits on the .dev TLD — which browsers hard-require HTTPS for — so there is no plain-HTTP path to downgrade to.
App previews run inside an iframe with sandbox="allow-scripts" and no allow-same-origin. Preview code executes in an opaque origin: it can’t read your session, your cookies, or the page around it.
We never store your password — only a bcrypt hash of it. Password resets use single-use tokens that expire in 60 minutes, and we store only a SHA-256 of each token, never the token itself.
Your login session is a signed, httpOnly, Secure cookie — not readable by JavaScript. Changing or resetting your password invalidates your other sessions.
Published apps are served with a Content-Security-Policy, X-Robots-Tag: noindex, and a no-referrer policy. Framing is restricted to growthh.dev, so other sites can’t embed your app.
Generation is rate-limited per IP and globally per day, and sign-in and password-reset endpoints are throttled — protecting the service and keeping it predictable.
No ads and no third-party tracking cookies. We don't sell your personal data. Payment card details go straight to Razorpay and never touch our servers. Your account and projects are hosted on infrastructure in India (Bangalore).
growthh is a young product and we're not SOC 2 or ISO 27001 certified — so we won't claim to be. If your team needs a formal security review or specific commitments, and we'll be straight with you about what we can and can't offer today. For how we handle data, see our .
Get started
Start building free
Five credits a month, no card required. See what you can ship in an afternoon.
