Trust & Safety

Security Standards

Your security is paramount. GWIN is built with defense-in-depth principles to ensure your code and data are always protected.

Client-Side Isolation

All code execution happens in sandboxed WebAssembly containers within your browser. No code is ever sent to external servers for execution.

End-to-End Encryption

Cloud-synced projects (Pro & Team) use AES-256 encryption at rest and TLS 1.3 for all data in transit. Your code is encrypted before leaving your device.

Content Security Policy

Strict CSP headers and iframe sandboxing prevent cross-site scripting, clickjacking, and injection attacks within the preview environment.

SOC 2 Type II Compliance

Our infrastructure undergoes annual SOC 2 Type II audits. Penetration testing is conducted quarterly by independent security firms.

Found a vulnerability? We operate a responsible disclosure program.

Report a Security Issue