Finvora
PrivacyTermsRiskSecurity
TRUST / SECURITY

Security at Finvora

Defense-in-depth controls for sessions, user data, provider credentials and production operations.

Security contact: production security contact

Current controls

  • Server-issued opaque sessions in Secure, HttpOnly and SameSite cookies.
  • Object authorization from the server session rather than browser-supplied user IDs.
  • Origin and CSRF validation for state-changing requests.
  • AES-256-GCM protection for stored profile, chat, attachment and preference data.
  • TLS termination, HSTS, restrictive browser headers, API request limits and SSE connection caps.
  • Non-root, read-only application containers with dropped capabilities and resource limits.
  • Automated tests, dependency audit, CodeQL analysis, integrity-checked backups and minimal public health responses.

Responsible disclosure

If you believe you found a vulnerability, do not access other users’ data or disrupt the service. Send reproduction steps, affected URL, impact and contact details to the production security contact. Allow reasonable time to investigate before public disclosure.

Scope and limitations

No system is invulnerable. The production operator maintains incident response, patching, backup restoration and credential-rotation procedures and reviews controls as the architecture and threat model change.

© 2026 Finvora.