CV to portfolio
Security boundaries designed around a private CV
Ownership checks, validated uploads, and isolated public snapshots reduce what any request can expose.
CV to portfolio
Scoped to the owner
Dashboard reads and writes are scoped to the authenticated owner.
CV to portfolio
Uploads are checked, not trusted
Uploads are identified by content, scanned, and stored under server-generated keys.
CV to portfolio
A narrow public surface
Public rendering imports no authoring, parser, AI, or private-storage path.
CV to portfolio
Passwords a page owner controls
Any page can be given its own share password, checked server-side, without exposing which pages exist to someone who doesn't have it.
CV to portfolio
Guessing a draft address fails the same way
An unpublished portfolio and a typo return the identical response, so probing addresses can't tell the two apart.
CV to portfolio
Reported, not guessed at
A security concern reaches the team directly through the contact page — no need to describe it publicly first.
CV to portfolio