Trust boundary
Security & API Permissions
The catalogue website does not request your Torn API key. Product-specific API access, key storage, and data transmission are disclosed on each verified product page.
Least privilege
Products should request only the access needed for their documented functions and keep unrelated capabilities outside the boundary.
Key storage
The catalogue has no shared key store. Each product documents whether a key stays browser-local or is sent to an isolated service for a specific verification purpose.
Data transmission
Server-backed products disclose what leaves the browser. Local-first products state when no separate backend is required.
User-initiated Torn actions
Where a tool can prepare or perform an action on Torn, the product documentation identifies the confirmation boundary. The catalogue itself performs no Torn account actions, and active product actions remain subject to the individual tool's verified safeguards.