Skip to content

Not verified

One account reading another account's data

Whether a signed in account can reach another account's records by changing an id. ShipReady does not create accounts, sign in, or call your functions, so this cannot be answered from outside.

Last updated September 20, 2026

Needs a signed-in account

Why a check from outside cannot see it

Answering this means creating two accounts on your app and using one to reach the other's data. That is an action on your product taken by a stranger, and no automated check on a public address should be doing it.

How to check it yourself

  1. 1Create two accounts and sign in to each in a different browser.
  2. 2Copy a record address from the first account and open it in the second.
  3. 3Repeat through the API rather than the interface, because the interface often hides what the API allows.

Sign in as two accounts in two browsers, copy a record address from one, and open it in the other.

What a Launch Review does instead

Launch Review, $199

A reviewer signs in with two accounts, tries to reach one account's records from the other, and records exactly what answered.

See what a Launch Review covers

Incidents that involved this

No incident in the library maps to this one yet.

See all nine items

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026