Current protections
The platform uses HTTPS, security headers, strict origin controls, protected session cookies, managed secrets, durable database storage, audit trails, and rate limits. Sensitive public access is held back until it meets the required launch controls.
- Secrets are held in managed vault storage, not source code.
- Email verification codes are short-lived and protected against replay.
- Private account fields are not exposed through public discovery.
Report a vulnerability
Send a concise report to srirangam@vizdea.com with the affected URL or component, reproduction steps, impact, and any mitigation idea. Do not post the issue publicly before we can investigate.
- Do not access data that is not yours.
- Do not disrupt the service or run automated attacks.
- Include a request ID if the issue produced one.
Scope and response
We assess reports based on reproducibility, impact, and affected users. We will coordinate remediation before public disclosure where appropriate. Product support questions should go to info@vizdea.com instead.