Features

Security: what is built into every Melta product

For anyone who runs a digital product without wanting to deal with encryption, password hashes or attack protection. At Melta these are not options but part of every product: sign-in, data storage, payments and abuse protection run through platform building blocks you neither configure nor maintain.

What you get

In a self-built product, security is usually what comes last. At Melta it comes with the build, because the delicate parts are never solved by the product itself:

Secure sign-in

Passwords are stored only as a salted hash, never in plain text. Password reset and email confirmation work through time-limited links.

An isolated database per product

Every product has its own data store. No other product can reach your data, and yours cannot reach anyone else's.

Encrypted without lifting a finger

Every connection to your product is encrypted with TLS, on your own domain too. Certificates are issued and renewed without you doing anything.

Abuse protection

Logins, registrations and forms are rate-limited per sender. Automated requests run into a wall before they cost compute or storage.

How it works

Your product's security does not depend on someone remembering everything during the build. The delicate parts are building blocks that Melta provides and checks:

  1. During the build - Sign-in, data access, payments, mail and AI run through fixed platform building blocks. The build is stopped when a product tries to solve one of them on its own, such as storing passwords its own way.
  2. In operation - Requests to your product are rate-limited, outbound connections are controlled, and every connection is encrypted. The preview is reachable only by you until you go live.
  3. At payment - Your product never sees card data. Your customer pays with the payment provider, your product only learns that payment was made. The keys live on the platform, not in the code.
  4. Afterwards - Errors from browser and backend land in monitoring, and improvements to the building blocks reach your product automatically with the next build.

What security does not mean here

To be honest: no product is unbreakable, and Melta promises no certification. What Melta does promise is that the mistakes most common in self-built products cannot happen in the first place: passwords in plain text, shared databases, keys in the code, open forms without rate limits. For anything beyond that, such as special requirements on data storage or contracts, there is the Enterprise plan with individual commitments.

Who this matters to

For businesses with a customer portal. Whoever manages customer data, documents and messages needs a sign-in that holds and data nobody else can read. Both are built in.

For founders with a SaaS product. A subscription product with accounts and payments is a worthwhile target. Rate limits, isolation and payments without your own keys remove the usual attack surfaces.

For practices and studios with a booking system. Whoever stores names, appointments and payments of their customers carries responsibility for them. The legal pages come from your details, the technology behind them from the platform.

What it costs

A concept uses only a few credits; after that your product runs on one plan per organisation that brings credits for building and changes every month. Security is not an extra line item. All the numbers are on the pricing page.

Frequently asked questions

How are passwords stored in my product?

Never in plain text. Sign-in uses a platform building block that stores passwords only as a salted hash and compares them at login. Password reset works through a time-limited link by email.

Can other products access my data?

No. Every product runs in isolation and has its own database. There is no shared data store between products, and one product cannot call another.

What happens when someone attacks the login?

Sign-ins, registrations and forms are rate-limited per sender. Whoever sends too many attempts in a short time is turned away before compute or storage is spent.

Does my product ever see card data or secret keys?

No. Your customer enters card data with the payment provider, and the keys for payments, email and AI live on the platform. Your product only hands over what is to be sold or sent.

Who keeps the security up to date?

The building blocks for sign-in, payments, mail and data access are part of the platform and maintained by Melta. Improvements reach your product automatically with every build.

Built securely, without you having to think about it.

A concept uses only a few credits. Sign-in, data storage and payments run through building blocks that Melta maintains.

Get early access