Security
What AttestProof does to protect accounts, imported rows, reviewer links and evidence packs, and what data it holds, stated plainly.
Accounts
- Passwords are hashed with scrypt (N=32768, r=8, p=1) and a random 16-byte salt. They are never stored or logged in clear text.
- Passwords must be at least 10 characters, must not appear on a list of 1,000 common passwords, and must not contain your email address.
- Sessions are server-side and revocable. The cookie is HttpOnly, SameSite=Lax and, in production, Secure with the
__Host-prefix. Sessions expire after 30 days of inactivity and can be ended from Security. - Sign-in is limited to 10 attempts per minute per IP address and 20 per hour per email address.
- Email verification and password reset links are single-use, expire (24 hours and 30 minutes), and are stored only as hashes.
Tenancy
Every table that holds customer data carries the account id, and every query filters by it. Object ids are random and unguessable, but access never relies on that: a request for another account's object returns "not found".
Imported files and reviewer links
- Imports are accepted only when their content is CSV or plain text, regardless of file name, at most 10 MB. Files are stored under generated names outside the web root and the SHA-256 of every import is recorded and printed on the evidence pack.
- Reviewer links carry a 32-byte random token. The database stores its SHA-256 for lookup and a copy encrypted with the server key (AES-256-GCM) so the account can show the link again on the Reviewers page; raw tokens are never logged. A link shows only that reviewer's rows, stops working when it is replaced (delegation, "New link", email change) and expires 30 days after the review closes.
- Every reviewer action is recorded with the UTC time, IP address and browser, and the page tells the reviewer so before they decide.
- Auditor share links (Pro) are stored as hashes, expire after 14 days by default (up to 90), can be revoked at any time, and record every view and download.
Evidence packs and the hash chain
- Events are chained per account with SHA-256; the chain can be verified at any time and a break is reported, not hidden. Every decision, delegation, submission, revocation follow-through, close and pack generation is an event.
- Evidence packs print the chain head at generation time and carry an integrity page with the SHA-256 of the document body. The file hash is recorded in the chain so it can be checked on the public verify page. Packs are stored as files and served byte for byte; a download never regenerates the document.
What data is held, and for how long
- The rows you import (identifiers, entitlements, optional descriptions, last logins, managers and notes), each reviewer's decisions and comments, and the timestamp, IP address and browser of every reviewer action.
- Rows and reviewer records of a closed review are deleted after 12, 24 or 36 months (your setting; default 24). Evidence packs are kept. "Delete review data" on a review removes its rows, campaigns, packs and share links immediately; the event history keeps the hashes.
- Account deletion, on request to [email protected] from the owner's address, removes rows and uploads immediately and purges packs after 30 days unless they were downloaded.
- Outbound email to reviewers requires a verified account address and is capped per account per hour; every reviewer email says who is asking, why, and how to report misuse.
Transport and browser
- All traffic is served over HTTPS with HSTS. Requests arrive through Cloudflare.
- A strict Content Security Policy allows scripts and styles only from this origin, forbids inline scripts and framing, and restricts where forms may submit.
- Every state-changing request carries a per-session CSRF token and must originate from this site.
- Requests are rate limited (300 per minute per IP; 10 per minute on sign-in and token endpoints).
Operations
- Logs contain request ids, paths and timings. They never contain passwords, session ids, tokens or file contents.
- The database is backed up nightly; backups are kept for 14 days.
- Payment details are handled by Stripe through the InfiniHash App Store. AttestProof never sees card numbers.
Reporting a problem
If you believe you have found a security issue, email [email protected] with "security" in the subject. We acknowledge reports within two business days and do not pursue researchers who act in good faith.