Security

What the software does to protect accounts, sessions and files on your server, and what it deliberately does not claim. Last updated: 2026-08-24.

Thingfile is self-hosted, so the security of any given catalog is partly the software's job and partly the operator's. This page is the software's half: what it does today, stated so that where something is not done it says so rather than leaving you to assume.

Passwords

Passwords are hashed with Argon2id, the memory-hard algorithm recommended for password storage. The plaintext is never stored and never logged. A minimum strength policy is enforced at registration, and signing in takes the same amount of work whether or not the account exists, so the login form cannot be used to discover who has an account.

Sessions

Signing in issues an opaque 32-byte random token, not a JWT, so it carries no readable claims. Only a SHA-256 of it is stored, so the session table is not a list of usable keys. Sessions expire after a period of inactivity and carry a hard ceiling regardless of use, so a session cannot live forever. Signing out revokes the token immediately, and you can revoke every session on your account at once from any device.

Photos and files

Item photos and attachments go to a private bucket or directory that is not publicly reachable. They are served back only through the authenticated API, checked against the account that owns them. There is no shareable direct URL, and one account cannot read another's files by guessing an id.

In transit

The deploy module ships an nginx configuration that terminates TLS and sets HSTS, nosniff and framing headers. Serving your instance over HTTPS is ultimately the operator's call, and it is the one piece of this the software cannot make for you.

Abuse limits

Sign-in and registration are rate limited per network address. Image scanning and photo uploads (the operations that cost real work) are limited per account, so one busy account cannot degrade the service for others.

Your half of it

Running an instance means the parts no application can do for you: keep the host patched, keep the database backed up and test that a backup restores, put it behind TLS, and decide who gets an account. If you enable image scanning, that also means the credentials it uses to call the model provider.

What Thingfile does not claim

  • It is not end-to-end encrypted. The server can read the catalog and the photos on it. That is what makes server-side search and image labelling possible. On a personal instance that server is yours, which is rather the point; but if you run one for other people, they should know you can read their things.
  • Password reset is not built yet. There is no email delivery in the system, so a forgotten password cannot currently be recovered self-service.
  • Email addresses are not verified at registration, for the same reason.

Reporting a problem

Email security@spergs.com. Please report privately rather than publicly, and give us a reasonable window to fix the issue before disclosure. Tell us what you did, what you expected, and what happened. A request id from the X-Request-Id header on the response helps us find it exactly.

Contact

Thingfile is built and published by Spergs, LLC, a Florida limited liability company. We do not operate instances, so a report here is about the software rather than about any particular deployment.
Security: security@spergs.com
Privacy: privacy@spergs.com