border.bot

Security and data handling

border.bot runs on Cloudflare Workers, signs people in through WorkOS, takes payments through Stripe and records every credit movement in a ledger. This page explains each part and how to report a security issue.

Signing in and workspaces

  • Dashboard sign-in is handled by WorkOS AuthKit. Your session lives in an encrypted, signed cookie.
  • Work happens inside workspaces (organizations). Each member has a role: admins manage billing, API keys, the team and settings; members classify, calculate and see history.
  • Admin tooling is protected by Cloudflare Access (Zero Trust) and every request to it is verified.

Keeping workspaces apart

  • Each workspace’s data is separated by the database itself. Postgres row-level security only lets a request see and change the rows of the workspace it was authenticated for, even if application code asks for something else.
  • Each part of border.bot connects with its own database login that can do only what that part needs. The customer dashboard can’t read across workspaces at all, and the credit ledger can only be added to, never edited or deleted.
  • Automated tests run as those real database logins on every change and try to read and write across workspaces.

API keys

  • Keys are created per workspace, start with bb_live_ and are shown once.
  • We store only a hash of each key, never the key itself, so a leaked database would not reveal usable keys.
  • Admins can revoke a key at any time; revoked keys stop working immediately.

AI assistants (MCP)

  • The MCP server uses OAuth 2.1. You sign in on border.bot; the assistant receives a scoped token, not your password.
  • When you approve a client you choose which workspace it may bill.
  • Every connection is listed in the dashboard and can be revoked at any time.

Credits and payments

  • Prices are stored on our servers. A client only says which action or credit pack it wants, never how much it costs.
  • Each billable call debits credits in a single atomic transaction before it runs; a database constraint makes a negative balance impossible, even under heavy concurrency.
  • If a call fails, its credits are refunded automatically, and every movement is recorded in the credit ledger.
  • Payments go through Stripe Checkout. Card details never touch our servers, and credits are added only after Stripe’s signed webhook confirms the payment.

Free tools

  • The free classifier, calculator and origin finder are protected by Cloudflare Turnstile and rate limits.
  • Free runs are counted per visitor using keyed hashes of the IP address, its address range and a signed first-party cookie (bb_vid), and aren’t offered from VPN, hosting or Tor networks. We don’t store raw IP addresses for this.

Your product data

  • Descriptions, product URLs and values you submit are used to produce your result and are kept in your workspace history so you can find them again.
  • When you classify from a URL, we fetch that public page to read the product details (see how our page fetcher works at border.bot/bot).
  • Classification and duty calculation are performed with a specialist trade-data provider that receives the product details needed to produce the result.
  • Data is stored in PlanetScale Postgres, reached through Cloudflare, and in Cloudflare R2. Our main processors are Cloudflare, PlanetScale, WorkOS, Stripe and our trade-data provider.

Report a security issue

If you think you’ve found a vulnerability, email us with the details and steps to reproduce. Please don’t access other people’s data or degrade the service while testing. We’ll acknowledge your report and keep you updated while we fix it.

Email support@border.bot with “Security” in the subject. For anything else, see contact.