Security
Updated October 7, 2026
Website protections
DebutDock uses HTTPS and browser security headers, including a Content Security Policy with per-response script nonces, Strict Transport Security, frame restrictions, content-type protection and a referrer policy. Browser API requests that change data are checked for the expected origin; Stripe webhook requests use signature verification.
Payments and creator links
DebutDock subscription payments use Stripe checkout. Purchases directly from creators are separate transactions. Review external links, creator terms and payment destinations before proceeding. Never share account passwords, recovery codes or wallet seed phrases in a listing or support message.
Report a concern
Email hello@debutdock.com with the affected URL, what happened and safe steps to reproduce the issue. Remove personal information and secrets from screenshots. Do not access another user’s information, disrupt the service or send private keys.
Scope
These protections are not a certification or a guarantee that all vulnerabilities have been eliminated. Public website scores do not verify every account, database or payment control.