Manage your sign-in.
Account settings show your sign-in method and verification status. “Sign out all sessions” lets you end account sessions across devices.
From personal sign-in settings to project roles and client permissions, Gostrax gives your agency distinct places to manage access and review the next update.
Account settings show your sign-in method and verification status. “Sign out all sessions” lets you end account sessions across devices.
Team settings manage organization members, invitations and roles. Project access is configured separately, so organization membership does not automatically describe a member’s project permissions.
Clients use a separate project space. Dashboard access gates the other client capabilities, while content editing and publication require their own permissions.
The dashboard separates personal account settings from Team & access. Agency administrators can inspect active members and pending invitations, update authorized roles and revoke access. Ownership transfer requires an explicit confirmation in the interface.
Read access FAQs ↗Project roles are managed independently of organization roles. The project owner retains full access.
| Project role | Scope | Use it for |
|---|---|---|
| No access | No assigned project access. | Members who do not work on that project. |
| Viewer | View the project and available analytics. | Read-only project visibility. |
| Editor | Edit content, design and code; use AI tools. | Teammates preparing project changes. |
| Admin | Editor access plus publication and management of project settings, secrets and members. | Teammates responsible for project administration. |
Client text drafts are limited to pages selected by the agency. Media, articles, statistics exports and publication are separately configurable. Turning off dashboard access disables its dependent client capabilities.
Saving a draft, submitting it and reviewing it are distinct states. Client publication permission does not grant agency approval rights. Publication also depends on the project’s GitHub, Vercel and service configuration.
GitHub import uses repositories authorized for the connected GitHub App. Imported source should be trusted and reviewed. Agency expert mode is the separate tool for direct source edits.
The project ZIP export is designed to exclude secret environment files, dependencies and generated build output. Review your source before sharing it: credentials embedded directly in ordinary code are still sensitive.
Protected project operations evaluate the authenticated user, organization context, project role and required capability. Interface visibility alone is not the authorization model.
Authentication flows validate the application origin. Rate-limit policies cover authentication and selected AI operations. The early access endpoint validates input and restricts allowed origins.
These controls are present in the project. Their production operation depends on configuration and deployment. No independent audit, security certification or uptime commitment is claimed here.
Contact Denis Franchi with the affected feature, reproduction steps and potential impact. Use “Gostrax security report” as the subject and start with redacted evidence. Do not send passwords, tokens or private client data.
denis@denisfranchi.dev ↗Only test accounts and projects you are authorized to access. Avoid destructive testing, accessing another person’s data or disrupting the service.
Marketing privacy notice ↗Help & FAQs ↗