Production secrets and customer data are stored outside the public web root with restricted access, health checks and backup procedures.
Security
Account protection at every stage.
Security is treated as an operational process covering registration, authentication, recovery, billing, provisioning and mail delivery—not as a single marketing feature.
Account safeguards
These controls are built into the account service and covered by automated tests.
- Argon2id password hashing
- HTTP-only, same-site session cookies
- CSRF protection on state-changing forms
- Time-limited, one-use verification and reset tokens
- Authenticator-based two-factor authentication and one-use recovery codes
- Rate limits on registration, login and recovery
- Signed and idempotent Stripe webhook processing
- Administrative audit records
- Short-domain activation lock
Operational security
Protection continues beyond sign-in.
SPF, DKIM, DMARC, TLS, spam controls and outbound abuse limits protect the hosted mail service and its reputation.
Customers can use authenticator-based two-factor protection, separate mailbox passwords and verified recovery workflows.
Responsible reporting
Security concerns can be reported to security@privateaccess.space.
