WendingAIWENDINGAIAI Infrastructure
TRUST & SECURITY

Security practices you can understand.

WendingAI documents the controls that are actually implemented across authentication, sensitive credentials, partner operations and administrative workflows. We do not claim certifications we have not earned.

IDENTITY & SESSION

Reduce unnecessary credential exposure.

Authenticated areas are designed around server-side session state so full credentials do not need to live in browser storage.

HttpOnly sessions

Signed-in user, partner and administrator areas use HttpOnly session cookies so JavaScript cannot directly read the session token.

Human verification

Selected sensitive entry points use Cloudflare Turnstile, with short-lived trusted verification reuse for normal follow-up operations.

Mutation protection

Administrative and partner mutations use same-origin session checks and CSRF tokens where implemented.

CREDENTIALS

Sensitive values stay behind narrower interfaces.

The product is structured so different roles receive the minimum configuration surface required for their job.

End users

  • Account pages show masked credentials by default
  • Full API keys are fetched only when needed for authenticated setup workflows
  • Signing out clears the current device session without deleting account rights

Partners

  • Partners cannot read upstream API keys or platform secrets
  • Pricing and reward boundaries are enforced server-side
  • Partner sites and referral ledgers are isolated by site context
OPERATIONS

Operational controls are part of security.

Security is not only authentication. WendingAI also limits who can change product configuration, partner settings and high-impact operational state.

01

Audit trails

Sensitive administrative changes can be recorded for later review and accountability.

02

Site isolation

Host-scoped site configuration keeps partner branding, pricing and referral policy from leaking across sites.

03

Fail-closed choices

Selected production security paths are designed to fail closed when required security storage or verification is unavailable.

TRANSPARENCY

What we do not claim.

WendingAI should earn trust through verifiable controls and transparent operating practices.

We do not claim SOC 2 certification unless and until an applicable audit is completed.We do not claim ISO 27001 certification unless and until certification is formally obtained.We do not publish invented uptime percentages or security guarantees.

Need to evaluate WendingAI for a business deployment?

Review live platform status and contact WendingAI for deployment-specific security questions.