How Skate handles your app and your users.
Skate runs in the user’s tab, as that user. Here is what it sees, what it sends, and what you control.
Acts as the user
Same session, same permissions. No backend access and no API keys from you.
Keys stay on the server
The script in your page holds no secrets. Only origins you register can call the service.
What leaves the page
- The user’s request.
- Visible controls, labels and text of the current screen.
- Path, method and status of same-origin requests. Response bodies are off by default.
What never leaves
- Password, card-number and one-time-code fields.
- Text that looks like a token or card number. Redacted in the browser.
- Cookies, request headers and request bodies.
- Anything inside
data-private.
Approvals
Sends, deletes, payments and anything irreversible wait for the user to approve, with the consequence written out. Typed confirmations are left to the person.
Owner controls
- Turn it off per site at any time.
- Spend caps per site and per visitor.
- A session log, plus an inbox for results flagged as wrong.
Honest results
Done only when the page shows the result. Partial is reported as partial. Unconfirmed is reported as unconfirmed.
In progress
A DPA, a retention policy and a security contact process are being prepared. Design partners get them before going live. Questions: write to us.