This page describes the security practices actually implemented in Adsevon today. It is a statement of fact, not marketing: we do not claim certifications we do not hold.
What we do
- Encrypted connections. All traffic is served over HTTPS (TLS); security headers including HSTS are enforced in production.
- Password protection. Passwords are hashed with bcrypt (cost factor 12). Plaintext passwords are never stored and never logged. New passwords are checked against known breach data.
- Revocable sessions. Sessions are stored server-side in our database with a 30-day absolute lifetime, HttpOnly + Secure + SameSite cookies, and are revoked on password reset. No session tokens live in browser storage.
- Tenant isolation. Every data query is scoped to your workspace; automated tests verify that no workspace can read or modify another's data.
- Single-use tokens. Email verification and password-reset tokens are 256-bit random values, stored hashed, expiring after 24 hours and 30 minutes, and consumed atomically so they cannot be reused.
- Rate limiting. Login, signup, password reset, imports, and API actions are rate limited; production uses a shared Redis-backed limiter so limits hold across all servers.
- Audit logging. Authentication events, imports, recommendation changes, and settings changes are written to an append-only audit trail.
- Safe file handling. Uploads are size- and shape-limited, parsed defensively, never executed, and raw bytes are cleared after a successful import.
What we do not claim
Adsevon has not undergone SOC 2, ISO 27001, or similar third-party security audits, and we do not claim formal GDPR/CCPA certification. We follow privacy-by-design practices (see our Privacy Policy), and our policies will be reviewed by counsel before public launch.
Report a vulnerability
If you discover a security issue, please email security@adsevon.com. We will acknowledge receipt promptly and work to resolve verified issues quickly. Please do not access other customers' data while investigating.