Trust boundary

Security & API Permissions

The catalogue website does not request your Torn API key. Product-specific API access, key storage, and data transmission are disclosed on each verified product page.

Least privilege

Products should request only the access needed for their documented functions and keep unrelated capabilities outside the boundary.

Key storage

The catalogue has no shared key store. Each product documents whether a key stays browser-local or is sent to an isolated service for a specific verification purpose.

Data transmission

Server-backed products disclose what leaves the browser. Local-first products state when no separate backend is required.

User-initiated Torn actions

Where a tool can prepare or perform an action on Torn, the product documentation identifies the confirmation boundary. The catalogue itself performs no Torn account actions, and active product actions remain subject to the individual tool's verified safeguards.