LEGAL
Security Policy
1. Our Security Commitment
Security is a core part of Uzvera’s design — not an afterthought. We build with a security-first approach across authentication, data storage, network transport, and access control.
2. Authentication & Session Security
- Passwords are hashed with Argon2id — a memory-hard, industry-leading algorithm.
- Sessions use opaque, hashed tokens stored server-side with a configurable expiry.
- TOTP-based two-factor authentication (2FA) with encrypted secret storage.
- Single-use recovery codes, each hashed before storage.
- Account lockout and email-based rate limiting to prevent brute-force attacks.
- Sign-in security notices sent to your email after new logins.
3. Data Protection
- All data in transit is encrypted via TLS.
- Strict tenant isolation — no organization can access another’s data.
- Device enrollment uses Ed25519 signed, one-time codes to bind device identity.
- Signed, expiring tokens are used throughout authentication flows (email verification, password reset, invitations).
- CSRF protection on all state-changing operations.
- Security headers enforced on all responses: CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy.
4. Infrastructure & Access
- The super-admin console is restricted to designated internal accounts and is inaccessible to regular users.
- Role-based access control (RBAC) is enforced on all API endpoints and UI actions.
- All significant account and inventory changes are written to an immutable audit log.
- The platform is under active development — additional security controls are tracked openly in our developer roadmap.
5. Known Limitations (Preview)
Uzvera is currently in preview. The following production security controls are pending verification or completion:
- Production SMTP delivery and sign-in notice arrival verification
- Trusted proxy IP-header deployment verification
- Strict production Content Security Policy
- Tenant isolation integration test coverage
- Dependency scanning in CI
We disclose these limitations openly. We will update this page as each item is resolved.
6. Vulnerability Disclosure
If you discover a security vulnerability in Uzvera, please report it responsibly. We ask that you:
- Do not publicly disclose the vulnerability before we have had a chance to address it.
- Do not access, modify, or delete data belonging to other users.
- Send your report to security@uzvera.com with:
- A clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Any proof-of-concept code (if applicable)
We aim to acknowledge reports within 2 business days and to provide an initial assessment within 7 business days. We are grateful to researchers who help us keep Uzvera secure.
7. Contact
Security reports and questions: security@uzvera.com
