News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…News here:Weblooks now supports Antigravity!Read more here…
Weblooks

Platform guides

How Weblooks keeps your site and account secure

Security is not a settings page you visit once. It is built into how you sign in, what each person can touch, and what gets recorded.

Signing in#

The default sign-in is a magic link sent to your email, so there is no password to reuse, leak, or forget. Passkeys are supported for one-tap sign-in with your device's own unlock (Face ID, fingerprint, or PIN). Passwords are available only with multi-factor authentication enabled, so a stolen password alone is never enough to get in.

Roles and permissions#

Every person in a workspace has an explicit role: owner, admin, editor, reviewer, or a client invite (read-only or comment-only). Each role gets the least access it needs. Clients can never reach source code, deploy controls, or configuration, and reviewers cannot change what they review. There are no hidden capabilities to remember.

Audit logs#

Sign-ins, invites, approvals, deploys, and rollbacks are recorded with who did what and when. If a client claims they never approved a page, or you need to know who promoted a deploy on a Friday evening, the answer is in the audit log rather than in anyone's memory.

Your site and your data#

Staging deploys are immutable and only go live after an automatic health check, so a broken upload cannot silently replace a working site. Rollback is one click and is itself audited. Payment details are handled by the payment processor and never stored by Weblooks.