Security and privacy
Private by architecture, not by slogan
Hear Me Later applies layered controls to authentication, files, release decisions, recipient access, and administrative operations.
Account protection
Email verification, strong password hashing, two-factor authentication with recovery codes, secure API tokens, biometric app locking, rate limits, and new-device alerts protect sign-in flows.
File protection
Private files are encrypted with per-file keys, kept outside the public document root, and decrypted only through an authorization-checked stream. Signed links are short lived and do not reveal storage paths.
Operational accountability
Sensitive actions carry request identifiers and audit events. Administrative roles are permission limited, and private message or document contents are not copied into routine logs.