Security
Your security is our top priority. Learn about the comprehensive measures we implement to protect your data and maintain platform integrity.
Data Encryption
We employ industry-leading encryption technologies to protect your data at every stage:
Authentication & Access Control
We implement multiple layers of authentication and access control to protect your account:
Password Security
- Minimum 12 characters with complexity requirements (uppercase, lowercase, numbers, special characters)
- Breach detection - passwords checked against known compromised credential databases
- Secure password hashing using Argon2id with bcrypt as a fallback
- Password history - prevents reuse of recent passwords
Multi-Factor Authentication (MFA)
- Authenticator apps (TOTP) - time-based one-time codes from any standard authenticator app
- Passkeys & security keys (WebAuthn/FIDO2) - phishing-resistant, hardware-backed sign-in
- Single-use backup codes - secure account recovery when your device is unavailable
Session Security
- Secure session cookies with HTTPOnly and SameSite=Strict flags
- Session timeout after 480 minutes of inactivity
- Session regeneration on login to prevent fixation attacks
- Concurrent session limits with ability to view and revoke active sessions
Brute-Force Protection
- Rate limiting - 5 login attempts per 5-minute window
- Progressive delays on failed authentication attempts
- Account lockout after repeated failed attempts
- IP-based monitoring for suspicious activity patterns
Application Security
Our application is built with security-first principles and protected against common web vulnerabilities:
Security Headers
Attack Prevention
- CSRF Protection: All forms and actions protected with cryptographically secure tokens
- SQL Injection Prevention: Parameterized queries using PDO throughout the application
- XSS Prevention: Strict output encoding and Content Security Policy enforcement
- Input Validation: All user inputs validated and sanitized server-side
- File Upload Security: Strict file type validation and isolated storage
Infrastructure Security
Our infrastructure is designed with defense in depth, providing multiple layers of protection:
Network Security
- Web Application Firewall (WAF) filtering malicious traffic
- DDoS Protection with automatic mitigation
- Network segmentation isolating different system components
- Regular vulnerability scanning and penetration testing
Server Security
- Hardened server configurations following CIS benchmarks
- Regular security patches and updates
- Minimal attack surface with only essential services running
- Intrusion detection and monitoring systems
Database Security
- Encrypted database connections using TLS
- Access controls limiting database privileges
- Regular backups with encryption
- Audit logging of database access and modifications
Compliance & Data Protection
Our security practices are designed to meet or exceed regulatory requirements across multiple jurisdictions:
Data Protection Measures
- Data minimization: We collect only necessary data for service provision
- Purpose limitation: Data used only for specified, legitimate purposes
- Storage limitation: Data retained only as long as necessary
- Privacy by design: Security built into every feature from the start
- Data subject rights: Full support for access, rectification, erasure, and portability requests
Incident Response
We maintain comprehensive incident response procedures to quickly address any security issues:
Response Process
- Detection & Analysis: Automated monitoring and manual review identify potential incidents
- Containment: Immediate steps to limit impact and preserve evidence
- Eradication: Remove the threat and address root causes
- Recovery: Restore normal operations with enhanced safeguards
- Post-Incident Review: Document lessons learned and improve defenses
Breach Notification
In the event of a data breach affecting your personal information:
- Regulatory notification: Relevant authorities notified within 72 hours as required by GDPR/UK GDPR
- User notification: Affected users informed without undue delay if high risk to rights and freedoms
- Transparency: Clear communication about what happened, what data was affected, and remediation steps
Security Best Practices for Users
Help us keep your account secure by following these recommendations:
Recommended Actions:
- Use a strong, unique password (12+ characters with mixed case, numbers, symbols)
- Never share your login credentials with others
- Log out when using shared or public computers
- Keep your browser and operating system updated
- Be cautious of phishing emails claiming to be from us
- Review your account activity regularly for unauthorized access
- Use a password manager to generate and store strong passwords
- Report any suspicious activity to our security team immediately
Responsible Disclosure
We value the security research community and welcome responsible disclosure of vulnerabilities:
Reporting Security Issues
If you discover a security vulnerability, please report it responsibly:
- Email us at security@confidion.com
- Include detailed information about the vulnerability
- Provide steps to reproduce the issue
- Allow us reasonable time to address the issue before public disclosure
Our Commitment
- We will acknowledge receipt of your report within 48 hours
- We will provide regular updates on our progress
- We will credit researchers (if desired) when issues are resolved
Safe Harbor & Rules of Engagement
The points below are the rules of engagement and legal safe harbor for good-faith security researchers — not something we expect a malicious actor to honour, but the line that separates authorised research from an attack. If you act in good faith and stay within this scope, we authorise your testing, will not treat it as a breach of our terms, and will not pursue or support legal action against you. Step outside it and the safe harbor no longer applies.
To stay in scope and keep safe-harbor protection, please do not:
- Access, modify, or delete data belonging to other users — test only with accounts you control
- Run denial-of-service, volumetric, or load/stress attacks against our systems
- Use social engineering, phishing, or physical attacks against our staff or facilities
- Publicly disclose a vulnerability before we’ve confirmed it is resolved (coordinated disclosure)
Security Questions or Concerns?
Our security team is here to help. Contact us for any security-related inquiries.
security@confidion.com