We protect your data with the same standards used by Fortune 500 companies. Our platform was penetration tested across 11 attack categories on July 31, 2026, passing all tests with zero critical vulnerabilities found. Here is exactly how we secure every layer.
1. Authentication & Identity
Control
Implementation
Password Hashing
Argon2id, the strongest algorithm available. Winner of the Password Hashing Competition. Unique salt per password.
Password Policy
8+ characters, uppercase, lowercase, and number required. Enforced on registration, reset, and change.
Two-Factor Authentication
TOTP-based (RFC 6238) via authenticator apps. 8 single-use backup codes. Mandatory for admin accounts.
Account Lockout
5 failed attempts triggers automatic lock. Password reset via email unlocks brute-force locks. Admin-imposed locks are not affected by reset.
OAuth Providers
Google OAuth and LinkedIn OAuth for passwordless sign-in. Redirect URLs validated against domain whitelist. No passwords stored for OAuth users.
JWT Tokens
HS256-signed. Access tokens expire in 30 minutes with automatic silent refresh. Refresh tokens revoked on logout across all devices.
2. Session Security
Control
Implementation
Idle Timeout
60 minutes of inactivity triggers automatic logout. Every API call refreshes the timer.
Device Tracking
Browser, OS, device type, and IP recorded per session. Users can view and revoke sessions remotely.
Anomaly Detection
New device, IP, or browser triggers risk scoring. High-risk logins send email alerts to the account owner.
Token Revocation
Logout kills all refresh tokens. Account lock clears all sessions. No lingering access possible.
3. Web & API Protection
Control
Implementation
TLS Encryption
TLS 1.2+ with strong cipher suites. All traffic encrypted. HTTP automatically upgraded to HTTPS.
A comprehensive penetration test was conducted across all attack surfaces. Below are the complete results.
11/11 Tests Passed · 0 Critical Vulnerabilities
#
Test Category
Attack Vector
Result
1
Authentication
Admin endpoint exposure without valid token
✅ PASS, All return 401/403
2
Payments
Payment verification with fake transaction IDs
✅ PASS, Returns 404
3
Infrastructure
Quota bypass via simultaneous requests
✅ PASS, Properly queued
4
Payments
Plan upgrade without completing payment
✅ PASS, Backend validates
5
Authentication
JWT token manipulation (role escalation)
✅ PASS, Roles from DB
6
Payments
Crypto webhook forgery (fake IPN signatures)
✅ PASS, HMAC verified
7
Injection
SQL injection in search queries
✅ PASS, Parameterized queries
8
Injection
SQL injection in lead history filters
✅ PASS, Treated as literals
9
Authentication
Brute force login (8 rapid attempts)
✅ PASS, Locked after 5
10
Injection
XSS in registration (script tags)
✅ PASS, Returns 400
11
Injection
Referral code SQL injection
✅ PASS, Returns 400
9. Vulnerability Disclosure
If you discover a security vulnerability, please email Help Center. We request that you provide detailed reproduction steps and allow reasonable time for remediation before public disclosure. We treat all reports with the highest priority and aim to acknowledge within 24 hours.
10. Incident Response
In the event of a security incident affecting user data, affected users will be notified within 72 hours with details of the incident, data affected, likely impact, and remediation steps. A post-incident review will be conducted to prevent recurrence.