Security
Your security is our top priority. Learn about the comprehensive measures we implement to protect your data and maintain platform integrity.
Data Encryption
We employ industry-leading encryption technologies to protect your data at every stage:
Authentication & Access Control
We implement multiple layers of authentication and access control to protect your account:
Password Security
- Minimum 12 characters with complexity requirements (uppercase, lowercase, numbers, special characters)
- Secure password hashing using Argon2id with bcrypt as a fallback
- Password history - prevents reuse of recent passwords
Multi-Factor Authentication (MFA)
- Authenticator apps (TOTP) - time-based one-time codes from any standard authenticator app
- Passkeys & security keys (WebAuthn/FIDO2) - phishing-resistant, hardware-backed sign-in
- Single-use backup codes - secure account recovery when your device is unavailable
Session Security
- Secure session cookies with HTTPOnly and SameSite=Strict flags
- Session timeout after 480 minutes of inactivity
- Session regeneration on login to prevent fixation attacks
- Concurrent session limits with ability to view and revoke active sessions
Brute-Force Protection
- Rate limiting - 5 login attempts per 5-minute window
- Progressive delays on failed authentication attempts
- Account lockout after repeated failed attempts
- IP-based monitoring for suspicious activity patterns
Team & Role-Based Access Control
- Delegated roles - accounts support owner, administrator, manager, and member roles, so administrators can delegate user management without granting full control
- Member access suspension - administrators can disable or restore an individual member's access to the account at any time
- Per-resource sharing - saved searches, entity profiles, and data feeds can be shared read-only or read/write with specific members or groups within the account; cross-account isolation is always preserved
- Account audit log - user, role, and permission changes are recorded to an account-scoped audit trail visible to administrators
Application Security
Our application is built with security-first principles and protected against common web vulnerabilities:
Security Headers
Attack Prevention
- CSRF Protection: All forms and actions protected with cryptographically secure tokens
- SQL Injection Prevention: Parameterized queries using PDO throughout the application
- XSS Prevention: Strict output encoding and Content Security Policy enforcement
- Input Validation: All user inputs validated and sanitized server-side
- File Upload Security: Strict file type validation and isolated storage
Infrastructure Security
Our infrastructure is designed with defense in depth, providing multiple layers of protection:
Network Security
- Network segmentation β application, data and Tor-egress components run on separate isolated networks; the Tor gateway is reachable only by the feed workers
- Minimal exposed surface β a single published application port; the database and cache are not reachable from outside the internal network
- Rate limiting and IP blocking on authentication and API endpoints, with automated lockout on repeated failures
Server Security
- Privilege restriction β containers run with
no-new-privileges, and the analysis service runs as an unprivileged user - Automated dependency patching β weekly monitoring of PHP, Python and CI dependencies, with security advisories raised as pull requests
- Automated security testing in CI β every change runs a security test suite, dependency audit and dynamic application security scan before it can merge
- Application-layer security monitoring with automated alerting on anomalous access patterns
Database Security
- TLS for database connections, with server-certificate verification
- Least-privilege database roles β separate application, read-only and background-job accounts, with the read-only role required to differ from the application role
- Encrypted backups to a private, versioned store using a customer-managed key, with a SHA-256 integrity checksum for every upload
- Tamper-evident audit logging of security-relevant application events, HMAC-chained so removal or alteration of an entry is detectable
Data Residency
- Canadian hosting - production infrastructure and databases run in AWS Canada (ca-central-1)
- Canadian backups - encrypted database backups are stored in a private, public-access-blocked storage bucket in the Canadian region, protected with a customer-managed KMS key
Compliance & Data Protection
Our security practices are designed to meet or exceed regulatory requirements across multiple jurisdictions:
Data Protection Measures
- Data minimization: We collect only necessary data for service provision
- Purpose limitation: Data used only for specified, legitimate purposes
- Storage limitation: Data retained only as long as necessary
- Privacy by design: Security built into every feature from the start
- Data subject rights: Full support for access, rectification, erasure, and portability requests
Incident Response
We maintain comprehensive incident response procedures to quickly address any security issues:
Response Process
- Detection & Analysis: Automated monitoring and manual review identify potential incidents
- Containment: Immediate steps to limit impact and preserve evidence
- Eradication: Remove the threat and address root causes
- Recovery: Restore normal operations with enhanced safeguards
- Post-Incident Review: Document lessons learned and improve defenses
Breach Notification
In the event of a data breach affecting your personal information:
- Regulatory notification: Relevant authorities notified within 72 hours as required by GDPR/UK GDPR
- User notification: Affected users informed without undue delay if high risk to rights and freedoms
- Transparency: Clear communication about what happened, what data was affected, and remediation steps
Security Best Practices for Users
Help us keep your account secure by following these recommendations:
Recommended Actions:
- Use a strong, unique password (12+ characters with mixed case, numbers, symbols)
- Never share your login credentials with others
- Log out when using shared or public computers
- Keep your browser and operating system updated
- Be cautious of phishing emails claiming to be from us
- Review your account activity regularly for unauthorized access
- Use a password manager to generate and store strong passwords
- Report any suspicious activity to our security team immediately
Responsible Disclosure
We value the security research community and welcome responsible disclosure of vulnerabilities:
Reporting Security Issues
If you discover a security vulnerability, please report it responsibly:
- Email us at security@confidion.com
- Include detailed information about the vulnerability
- Provide steps to reproduce the issue
- Allow us reasonable time to address the issue before public disclosure
Our Commitment
- We will acknowledge receipt of your report within 48 hours
- We will provide regular updates on our progress
- We will credit researchers (if desired) when issues are resolved
Safe Harbor & Rules of Engagement
The points below are the rules of engagement and legal safe harbor for good-faith security researchers — not something we expect a malicious actor to honour, but the line that separates authorised research from an attack. If you act in good faith and stay within this scope, we authorise your testing, will not treat it as a breach of our terms, and will not pursue or support legal action against you. Step outside it and the safe harbor no longer applies.
To stay in scope and keep safe-harbor protection, please do not:
- Access, modify, or delete data belonging to other users — test only with accounts you control
- Run denial-of-service, volumetric, or load/stress attacks against our systems
- Use social engineering, phishing, or physical attacks against our staff or facilities
- Publicly disclose a vulnerability before we’ve confirmed it is resolved (coordinated disclosure)
Security Questions or Concerns?
Our security team is here to help. Contact us for any security-related inquiries.
security@confidion.com