TableSet
Security
Last updated October 1, 2026
How TableSet protects what you put into it, and how to tell us if you find a problem.
On every device
- Without an account, your work never leaves your browser. There is nothing on our side to break into.
- Untrusted text is cleaned. Anything that arrives from outside, such as a backup file and, with accounts, anything loaded from the server, is cleaned before it is shown. It keeps only bold, italic and line breaks.
- The site only runs its own code. A strict content security policy blocks scripts from anywhere else, and the site cannot be framed by other sites.
With a beta account
- Organizations are walled off by the database itself. Every list and inventory record belongs to one organization. The database refuses to read or change any of it for someone who is not a member, whatever the website asks.
- Every change is checked. Saves go through checks on who is asking, what their role allows and whether they are working from the latest version. A save that would overwrite someone else’s newer work is refused.
- Signing in is guarded. Passwords must be at least 10 characters and are checked against known breaches. Sign-in forms are rate-limited and protected from bots.
- Connections are encrypted, and data is backed up daily.
Reporting a problem
If you think you have found a security problem, please email help@tableset.wine with “Security” in the subject. Include what you found and how to see it. We will reply within 3 business days and keep you told until it is fixed.
Please do not read or change data that is not yours, and do not disrupt the service. We will not take action against anyone who reports a problem in good faith and follows these requests.