Skip to main content

Security

How it is built​

  • The editor runs in a frame on its own site (lettrove-embed.com). Your page cannot read inside it, and it cannot read your page. It has no cookies: browsers that block third-party cookies do not affect it.
  • Nothing secret is in your page. The page holds a publishable key (public by design) and a token that lasts at most fifteen minutes and opens one person's designs. Your secret key stays on your server.
  • It appears only on your sites. The browser refuses to show the editor on a site that is not on your project's list, and a token works only on the site it was minted for and with your project's own publishable key.
  • Your users are ids, not people. Lettrove does not accept their names or emails.
  • Your page's code never runs inside the editor, and the editor never runs code in your page beyond the small loader you install. The loader is open source (MIT) so your security team can read it.
  • What your users design is treated as data: an exported email is HTML for inboxes; previews inside the editor are shown in sandboxed frames that cannot run scripts.
  • Webhooks are signed (HMAC-SHA256, with a timestamp so they cannot be replayed), and Lettrove only ever calls public https addresses.

Your secret key​

  • Keep it in your server's environment or secret store. Never in a page, a mobile app, a repository, a log, a chat or an email.
  • @lettrove/node refuses to run in a browser, so it cannot end up in a page by accident.
  • A project can have two live secret keys at once, so you can rotate without downtime: make a new one, deploy it, then revoke the old one.

If a secret key leaks​

  1. Revoke it now: Settings → Embed → your project → Keys → Revoke. Every editor open with the project stops at its next request, and every token minted before is refused.
  2. Make a new secret key and deploy it to your server.
  3. Editors reopen as soon as your server mints tokens with the new key.

If you suspect anything else, or found a security problem in Lettrove: support@lettrove.com.

Stopping everything at once​

Settings → Embed → your project → Pause stops every open editor at its next request and refuses new ones, until you resume it. Your designs and settings are untouched.