MDNote.dev MDNote.dev Markdown workspace
Log In Sign Up

Security

Secure sessions and user isolation for your notes

MDNote.dev runs with an architecture that separates user notes from each other and protects the workspace with modern security standards.

Password hashing Session renewal User-based data isolation

Strong password storage

Passwords are never stored as plain text; they are kept with industry-standard strong hashing.

  • Hash-based storage
  • Session renewal after login
  • Password change flow

Brute-force protection

Failed login attempts are tracked and accounts are protected against unauthorized attempts.

  • Login attempt logging
  • IP and user signals
  • Progressive protection logic

User isolation

Each user only sees and edits their own notes; total data privacy is ensured.

  • Account-based data segregation
  • Folder and note ownership control
  • Unauthorized access prevention

Session

The login flow puts account security at the center.

Registration and login processes work with fundamental security practices like password hashing, active session checks, and session renewal. Suspicious attempts are monitored to keep accounts secure at the highest level.

  • No plain text password storage
  • Session regeneration on login
  • Throttling of failed attempts

Data boundary

Note access is protected by strict ownership rules.

In the MDNote workspace, each user's notes and folders are strictly independent. Database-level ownership verification prevents any cross-account data leaking or unauthorized access.

  • Account-specific workspace access
  • Security layer preventing unauthorized access
  • Database-level user data segregation

Your data is protected on the server side with secure sessions and isolated access controls.

Security practice

What should users pay attention to?

Account hygiene is as important as application security in protecting your notes.

Strong password

Choose a hard-to-guess password not used on other services.

Shared devices

Log out when you are done on shared computers.

Sensitive data

Follow your organization's policy when writing secrets, passwords, or customer data in notes.

Support notification

Report suspicious account behavior through the contact channel.

FAQ

Questions about security

How are my notes protected?

Your notes are protected with secure server sessions, strong password hashing, and account-level data isolation.

Can users access each other's notes?

No. Every user's workspace is strictly isolated. Through robust authorization checks, no user can view another user's notes or folders.

Are failed login attempts monitored?

Yes. The security infrastructure records failed attempts and shields accounts from brute-force attacks.

Secure start

Open an isolated note area with your own account.

After registration, your notes are kept safely and exclusively in your personal workspace.