Trust & security

How TXTNimble protects tools, payments and accounts

TXTNimble separates browser-only utilities, server-assisted writing, optional private AI and payment flows so each page can explain what leaves your device.

Processing boundaries

Client tools process working text or local files on the device. Assisted writing sends the submitted text to TXTNimble only for the requested result and usage logging stores lengths and counts rather than the text itself. Optional AI is disabled by default and is configured from Admin → AI Studio.

Application controls

  • Prepared database statements and CSRF protection on state-changing forms.
  • Rate limits on authentication, tool usage, contact and payment actions.
  • Server-side Razorpay order, signature, amount and currency verification before paid access is granted.
  • Administrator two-factor authentication with encrypted TOTP secrets and recovery codes.
  • HSTS, nosniff, referrer policy, permissions policy and a restrictive content security policy.
  • Public disclosure channel through security.txt.

Security ratings or third-party badges are not displayed unless a real, current profile is recorded by the operator.