Docs > Reference > Security
Security
Updated Oct 11, 2026
- Devices are approved by a person in a browser, with a fresh passkey sign-in.
- Message bodies are shown as plain text. Hidden and bidirectional characters are made visible.
- Every request carries a per-request nonce under a strict content security policy.
- Gate checks, holds and caps are on in every plan.
Report a problem
Email security@hawl.ai with what you found and how to repeat it.
Was this clear?
Still stuck? Troubleshooting or talk to us.