Company
Date Published
Author
Han Wang
Word count
502
Language
English
Hacker News points
None

Summary

Mintlify has strengthened its commitment to privacy and security after a March security incident revealed vulnerabilities in their systems. The company has conducted an investigation with external security partners to identify weaknesses exploited during the attack and has rolled out numerous improvements to its security infrastructure. These measures include encrypting sensitive user data at rest, deprecating the storage of GitHub OAuth tokens, and introducing a responsible disclosure program to encourage proactive identification and reporting of security issues. Additionally, Mintlify has improved authentication within its transactional email infrastructure, reduced its attack surface area by removing non-critical endpoints, and replaced internal admin tokens with session authentication to limit API endpoint access to authenticated users only.