Security
Your work stays with your team
A plain summary of how Teeme controls access and protects accounts. No buzzwords, just what the product does.
Access
People only see what their teams can see
Access follows your structure: organizations own projects and teams, and people reach projects only through teams.
Team-based project access
A project is visible only to members of teams that have been given access to it. The server checks this on every project request.
Roles and permissions
Organization roles carry granular permissions, so you decide who can invite people, manage teams or change projects.
Per-team project permissions
Limit what a team can do inside a project, such as creating or deleting issues and which settings sections it can open.
Accounts
Sign-in and sessions
Accounts are verified, sessions are kept out of reach of page scripts, and sign-in endpoints are rate limited.
JWT sessions in httpOnly cookies
Sessions use signed JSON Web Tokens stored in httpOnly cookies, which JavaScript on the page cannot read.
Email verification
New accounts confirm their email address. You can also sign in with Google or a one-time magic link.
Hashed passwords
Passwords are hashed with bcrypt before they are stored. We never keep them in plain text.
Rate limiting
Sign-in, invitation and general API requests are rate limited to slow down brute-force and abuse.
Data
Careful with what comes in
Requests are checked before they reach your data, and changes to issues leave a trail.
Input validation
Incoming request data is validated with Zod schemas on the server, and malformed input is rejected.
Issue change history
Each issue records changes to its status, assignee and fields, along with who made them and when.
Expiring invitations
Invitations use random tokens tied to an email address and a role, and they expire after 7 days.
Found a security issue?
Please tell us privately before disclosing it publicly, and we'll look into it as quickly as we can.
Get your team on one page
Free for small teams. Set up in a couple of minutes, or look around the live demo first.