Skip to main content

Technical & Security Background

Last Revised: September 12, 2026

Core Engine

GiselleBot is written in Node.js and TypeScript, and uses Discord.js v14 as its core Discord library.

In active development since 2017, GiselleBot has grown from a single bot into a multi-service system: a sharded core bot, a fleet of independent single-purpose backend microservices, a public API gateway, a dedicated Discord API rate-limiting proxy, a webhook ingestion service, and this web dashboard.

Infrastructure

The bot and its supporting services are hosted on dedicated infrastructure provided by Hetzner. Application traffic is split across the sharded bot process and a fleet of independent, single-purpose backend microservices sitting behind a public API gateway, backed by a MongoDB replica set and a Redis/Valkey cluster with automatic failover.

Application logs are collected into a self-hosted log store running on the same dedicated infrastructure. Credentials and other secrets are masked before logs are stored, and logs are kept for a limited period only.

Additionally, a small number of managed services are provided by Amazon Web Services (AWS):

  • Object storage buckets hosting temporary (encrypted) files sent to end-users via various commands.
  • A Secrets Manager storing encryption keys, API credentials, and database passwords used across the fleet.

Security

Below is a general overview of the security measures in place across GiselleBot's infrastructure and services. See also our Privacy Policy for how we handle your data.

Encryption in Transit

  • Server-to-server traffic between application hosts runs over an encrypted tunnel and never traverses the public internet in the clear.
  • Internal service-to-service calls are authenticated with a shared secret key, issued only to trusted internal services.
  • Public-facing endpoints (the dashboard and API gateway) are served exclusively over HTTPS/TLS.
  • Web traffic is protected by Cloudflare, with certificates automatically renewed via Let's Encrypt.

Encryption at Rest

  • All storage media are encrypted at the low level.
  • Sensitive data fields are additionally encrypted using AES-GCM, through a dedicated internal encryption service using per-service keys sourced from our Secrets Manager - never hardcoded or checked into source control.
  • Temporary files generated by bot commands are stored in encrypted object storage and automatically deleted after a limited retention period.
  • Passwords for encrypted files are never logged and can be deleted by users to remove them from Discord.

Authentication, Authorization, Auditing

  • Dashboard sign-in uses Discord OAuth2; we never see or store your Discord password. A successful login is exchanged for a short-lived access token plus a longer-lived refresh token, rather than a permanent session.
  • Requests are rate-limited at every layer - per Discord user in the bot, per user and network address at the API gateway, and globally for outbound calls to Discord's own API - to curb abuse and protect availability.
  • Administrative access to our infrastructure requires private keys and, in all cases, multi-factor authentication, and is never exposed directly to the internet.
  • Secrets and credentials are fetched from our Secrets Manager or passed via temporary environment variables - never stored in plaintext on disk.
  • Access and activity across our services, including bot commands and API gateway requests, is logged for auditing purposes.

Infrastructure Security

  • Each host is protected by a firewall, ensuring only necessary ports are open.
  • SSH access is never exposed directly to the internet.
  • Secret keys, tokens, and credentials are never stored locally in application code or configuration files; they are fetched from our Secrets Manager at runtime.
  • Databases are backed up on a regular schedule, with backups retained for a limited period in redundant storage.
  • Source code is stored in private, access-controlled Git repositories.

Reporting A Security Issue

If you believe you've found a security vulnerability in any of our Services, please report it to us responsibly by contacting us with a description of the issue and steps to reproduce it, before disclosing it publicly. We ask that you do not access, modify, or delete data that isn't yours while investigating an issue. We aim to acknowledge reports promptly and will keep you updated as we work on a fix.