Skip to content
Back home

live.link · A Melade product

Security

Draft prepared September 16, 2026. Attorney review pending.

This beta policy draft is prepared for legal review. It is not a certification of legal compliance or a completed legal agreement.

On this page

  1. Security for the beta service
  2. Account and agent access
  3. Published content and private access
  4. Controls have limits
  5. Report a vulnerability
  6. If you suspect unauthorized access

Security for the beta service

live.link is operated by Melade LLC, Pennsylvania, United States. This page describes the service’s security approach and how to report concerns. It is not a security certification, penetration-test report, uptime guarantee or assurance that every planned feature is available.

Protection depends on the deployed feature, your chosen audience and the information you publish. Keep independent copies of important work and review generated code before relying on it.

Account and agent access

Account sign-in uses the configured identity service. Production account cookies are host-restricted and use secure transport; account actions are subject to server authorization. Workspace access is checked separately from the fact that a person has signed in.

Agent credentials have explicit scopes and can be revoked through available account controls. Browser sign-in does not automatically authorize a separate agent. Keep credentials out of prompts, source repositories, shared screenshots and published files.

Published content and private access

Management pages and uploaded or generated frontend content use separate delivery origins. Customer frontend code must not receive management sessions or provider secrets. Private previews and restricted publications require the applicable current access proof.

Saved versions and the published version are distinct. Publishing updates a guarded reference to a saved version; failed changes should preserve the prior publication. Review the audience before publishing: a public address can be forwarded, indexed or copied, and its obscurity is not an access control.

Controls have limits

Turning off a publication or revoking a credential prevents the corresponding future authorized access; it does not erase copies someone already obtained. Deletion, recovery and backup handling are separate lifecycle processes described in the Privacy Policy.

Infrastructure providers process requests and operational records. Provider settings and feature availability can change. We do not claim end-to-end encryption, zero retention across providers, a particular compliance certification or an automatic security review of all customer code.

Report a vulnerability

Email info@live.link with “Security report” in the subject. Include the affected feature or address, a concise description, expected versus observed behavior and safe reproduction steps. Include a request or error identifier if available. Redact credentials, private content and unrelated personal information.

Use only accounts and content you are authorized to test. Stop if testing reveals another person’s information; report the minimum facts needed without downloading more. Do not disrupt service, bypass another customer’s access, conduct destructive testing or publish exploit details that expose users.

We may request further information through an appropriate channel. This page does not establish a paid bug bounty, legal safe-harbor agreement or guaranteed response time. For an urgent threat to life or safety, contact the appropriate emergency services.

If you suspect unauthorized access

Revoke affected agent connections where available, secure your identity-provider account and contact info@live.link. Review publication audiences and turn off affected public links if needed. Never email a password or token to us; describe which connection or project is involved instead.

live.link by Melade
Privacy PolicyTerms of ServiceContact