Portal Heaven

Security and architecture

Learn how Portal Heaven handles connection credentials, content sessions, direct playback, compatibility relays and secure deployment.

Credential handling

Connection credentials are encrypted before persistent server-side storage. Short-lived opaque content-session tokens let the HTTP playback view load connection metadata without putting provider credentials in its URL.

Media path

The player prefers direct provider-to-browser playback. Metadata, authentication and selected compatibility operations use the Portal Heaven backend. If the optional media relay is used, stream bytes pass through that relay for the duration of playback.

Deployment controls

Operators should use HTTPS for login and account operations, protect secrets outside source control, restrict proxy destinations, apply request limits, keep dependencies updated and monitor resource usage.

Report a vulnerability

Please follow security.txt. Do not include live provider credentials, personal data or exploit details in a public issue.