Adsevon

Security

Last updated: October 5, 2026

This page describes the security practices actually implemented in Adsevon today. It is a statement of fact, not marketing: we do not claim certifications we do not hold.

What we do

  • Encrypted connections. All traffic is served over HTTPS (TLS); security headers including HSTS are enforced in production.
  • Password protection. Passwords are hashed with bcrypt (cost factor 12). Plaintext passwords are never stored and never logged. New passwords are checked against known breach data.
  • Revocable sessions. Sessions are stored server-side in our database with a 30-day absolute lifetime, HttpOnly + Secure + SameSite cookies, and are revoked on password reset. No session tokens live in browser storage.
  • Tenant isolation. Every data query is scoped to your workspace; automated tests verify that no workspace can read or modify another's data.
  • Single-use tokens. Email verification and password-reset tokens are 256-bit random values, stored hashed, expiring after 24 hours and 30 minutes, and consumed atomically so they cannot be reused.
  • Rate limiting. Login, signup, password reset, imports, and API actions are rate limited; production uses a shared Redis-backed limiter so limits hold across all servers.
  • Audit logging. Authentication events, imports, recommendation changes, and settings changes are written to an append-only audit trail.
  • Safe file handling. Uploads are size- and shape-limited, parsed defensively, never executed, and raw bytes are cleared after a successful import.

What we do not claim

Adsevon has not undergone SOC 2, ISO 27001, or similar third-party security audits, and we do not claim formal GDPR/CCPA certification. We follow privacy-by-design practices (see our Privacy Policy), and our policies will be reviewed by counsel before public launch.

Report a vulnerability

If you discover a security issue, please email security@adsevon.com. We will acknowledge receipt promptly and work to resolve verified issues quickly. Please do not access other customers' data while investigating.