RowGuard security

RowGuard validates CSV text in memory. The application does not intentionally store request bodies or cell values, and its structured request logs exclude bodies, headers, URLs, user identities, column names, and cell values. Requests transit Cloudflare and RapidAPI under their respective service terms.

Controls

Report a vulnerability

Use GitHub private vulnerability reporting. Do not place credentials, customer CSV data, or exploit details in a public issue. Include the affected endpoint, impact, and minimal reproduction using synthetic data.

Scope and limitations

Formula detection is a conservative warning or rejection heuristic and is not complete spreadsheet sanitization. The MVP has no contractual uptime SLA. Current API behavior is defined by the OpenAPI contract.

Last reviewed: 2026-09-13. Return to RowGuard.