The security choices that shape every endpoint, secret, and session in KolayLogin.
__client HttpOnly cookie.X-Forwarded-Proto trust required.Email security@kolaylogin.com — we acknowledge within 24h. Coordinated disclosure preferred; we credit reporters in release notes once a fix ships.