zvera
FeaturesPricingDownloadDocsSign in
LEGAL

Security Policy

Last updated: 27 September 2026 · Uzvera, Pakistan

1. Our Security Commitment

Security is a core part of Uzvera’s design — not an afterthought. We build with a security-first approach across authentication, data storage, network transport, and access control.

2. Authentication & Session Security

  • Passwords are hashed with Argon2id — a memory-hard, industry-leading algorithm.
  • Sessions use opaque, hashed tokens stored server-side with a configurable expiry.
  • TOTP-based two-factor authentication (2FA) with encrypted secret storage.
  • Single-use recovery codes, each hashed before storage.
  • Account lockout and email-based rate limiting to prevent brute-force attacks.
  • Sign-in security notices sent to your email after new logins.

3. Data Protection

  • All data in transit is encrypted via TLS.
  • Strict tenant isolation — no organization can access another’s data.
  • Device enrollment uses Ed25519 signed, one-time codes to bind device identity.
  • Signed, expiring tokens are used throughout authentication flows (email verification, password reset, invitations).
  • CSRF protection on all state-changing operations.
  • Security headers enforced on all responses: CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy.

4. Infrastructure & Access

  • The super-admin console is restricted to designated internal accounts and is inaccessible to regular users.
  • Role-based access control (RBAC) is enforced on all API endpoints and UI actions.
  • All significant account and inventory changes are written to an immutable audit log.
  • The platform is under active development — additional security controls are tracked openly in our developer roadmap.

5. Known Limitations (Preview)

Uzvera is currently in preview. The following production security controls are pending verification or completion:

  • Production SMTP delivery and sign-in notice arrival verification
  • Trusted proxy IP-header deployment verification
  • Strict production Content Security Policy
  • Tenant isolation integration test coverage
  • Dependency scanning in CI

We disclose these limitations openly. We will update this page as each item is resolved.

6. Vulnerability Disclosure

If you discover a security vulnerability in Uzvera, please report it responsibly. We ask that you:

  • Do not publicly disclose the vulnerability before we have had a chance to address it.
  • Do not access, modify, or delete data belonging to other users.
  • Send your report to security@uzvera.com with:
    • A clear description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any proof-of-concept code (if applicable)

We aim to acknowledge reports within 2 business days and to provide an initial assessment within 7 business days. We are grateful to researchers who help us keep Uzvera secure.

7. Contact

Security reports and questions: security@uzvera.com

© 2026 Uzvera · Connect. Monitor. Control.
FeaturesPricingDownloadDocs
Privacy PolicyTerms of ServiceCookiesSecurityRefund PolicyDPA