DotSpider by Nymble

Security at DotSpider

DotSpider by Nymble uses read-only integrations, encrypted registrar credentials, and a zero-knowledge API Key Vault on Pro and Portfolio plans.

Registrar credentials

Integration tokens are encrypted at rest with AES-GCM using a server secret (CREDENTIALS_SECRET). They are not logged in analytics.

API Key Vault

Vault secrets use client-side PBKDF2 (600,000 iterations) and AES-256-GCM. The server never receives plaintext secrets. Losing your vault passphrase and recovery kit means we cannot recover data.

Transport and headers

Production runs on HTTPS with strict Content Security Policy on app routes, HSTS on the apex, and X-Frame-Options: DENY.

Reporting

Report concerns to hello@dotspider.com.

Can DotSpider read my vault secrets?

No. Vault payloads are encrypted in your browser; we store ciphertext and metadata such as last four characters and expiry.

Are registrar tokens write-capable?

You should issue read-only API tokens. DotSpider is designed for read-only sync unless a future feature explicitly requests write scope with your confirmation.

How is login protected?

Passwords use PBKDF2 hashing. Optional TOTP two-factor authentication is required before enabling the vault.