§ 04 · Security
Trust & protection
Baalvion treats security, isolation, and accountability as architecture — built in from the first commit, not added after the fact.
There are no stored passwords to steal. Identity is verified with short-lived, one-time email codes and signed sessions.
All traffic is served over HTTPS with HSTS, and sensitive data is encrypted at rest.
Each organisation’s data is isolated with row-level controls so tenants, currencies, and jurisdictions stay separated.
Staff and services hold only the access their role requires, with sensitive actions captured in an audit log.
Authentication endpoints are rate-limited and protected with human-verification to stop automated attacks.
Strict security headers, a content-security policy, and bot mitigation are enforced at the edge.
Our commitments to you
Responsible disclosure
If you believe you have found a security vulnerability, please report it privately to security@baalvion.com. We investigate every report and will not pursue good-faith research conducted under this policy.