Current controls
- Server-issued opaque sessions in Secure, HttpOnly and SameSite cookies.
- Object authorization from the server session rather than browser-supplied user IDs.
- Origin and CSRF validation for state-changing requests.
- AES-256-GCM protection for stored profile, chat, attachment and preference data.
- TLS termination, HSTS, restrictive browser headers, API request limits and SSE connection caps.
- Non-root, read-only application containers with dropped capabilities and resource limits.
- Automated tests, dependency audit, CodeQL analysis, integrity-checked backups and minimal public health responses.
Responsible disclosure
If you believe you found a vulnerability, do not access other users’ data or disrupt the service. Send reproduction steps, affected URL, impact and contact details to the production security contact. Allow reasonable time to investigate before public disclosure.
Scope and limitations
No system is invulnerable. The production operator maintains incident response, patching, backup restoration and credential-rotation procedures and reviews controls as the architecture and threat model change.