Security

Security is a product requirement.

Vizdea is built with layered security controls and a responsible reporting path.

Current protections

The platform uses HTTPS, security headers, strict origin controls, protected session cookies, managed secrets, durable database storage, audit trails, and rate limits. Sensitive public access is held back until it meets the required launch controls.

  • Secrets are held in managed vault storage, not source code.
  • Email verification codes are short-lived and protected against replay.
  • Private account fields are not exposed through public discovery.

Report a vulnerability

Send a concise report to srirangam@vizdea.com with the affected URL or component, reproduction steps, impact, and any mitigation idea. Do not post the issue publicly before we can investigate.

  • Do not access data that is not yours.
  • Do not disrupt the service or run automated attacks.
  • Include a request ID if the issue produced one.

Scope and response

We assess reports based on reproducibility, impact, and affected users. We will coordinate remediation before public disclosure where appropriate. Product support questions should go to info@vizdea.com instead.