Security

Clear boundaries. Checkable evidence.

Controls in the current public naming service, shared shortlists, and private operating connection. Updated October 2, 2026.

Public assistant access
Search, domain checks, refinement, and comparison use the same evidence service as the website. Public MCP tools cannot purchase domains, change DNS, or access private operating data.
Provider evidence
Domain facts are normalized from registrar and marketplace responses. AI evaluates naming fit; it cannot establish availability, a price, or ownership. Responses retain their source and check time.
Shared shortlist access
Sharing creates separate random viewing and revocation keys. The service stores hashes of those keys. Viewing keys travel in the link fragment and are sent to the API in an authorization header. Links expire after 30 days and can be revoked from the browser that created them.
Private company operations
Rufio operators require a dedicated company permission. Public customer access and ordinary workspace membership do not grant operating access. Provider credentials stay on the server.
Request controls
Public requests use shared rate limits, bounded input sizes, validated schemas, and provider deadlines. A missing source or failed check remains unknown.
Operating records
The current search report uses daily aggregate counts without retaining briefs, domains, IP addresses, or customer identifiers in those records. Shared shortlist content has its own explicit sharing and expiry controls.

Report a security issue to security@names.dev. Include the affected page and steps to reproduce it without sharing passwords, provider keys, or someone else’s private data.

Read how we handle search and sharing data.