Security and architecture
Learn how Portal Heaven handles connection credentials, content sessions, direct playback, compatibility relays and secure deployment.
Credential handling
Connection credentials are encrypted before persistent server-side storage. Short-lived opaque content-session tokens let the HTTP playback view load connection metadata without putting provider credentials in its URL.
Media path
The player prefers direct provider-to-browser playback. Metadata, authentication and selected compatibility operations use the Portal Heaven backend. If the optional media relay is used, stream bytes pass through that relay for the duration of playback.
Deployment controls
Operators should use HTTPS for login and account operations, protect secrets outside source control, restrict proxy destinations, apply request limits, keep dependencies updated and monitor resource usage.
Report a vulnerability
Please follow security.txt. Do not include live provider credentials, personal data or exploit details in a public issue.