Security

Account protection at every stage.

Security is treated as an operational process covering registration, authentication, recovery, billing, provisioning and mail delivery—not as a single marketing feature.

Account safeguards

These controls are built into the account service and covered by automated tests.

  • Argon2id password hashing
  • HTTP-only, same-site session cookies
  • CSRF protection on state-changing forms
  • Time-limited, one-use verification and reset tokens
  • Authenticator-based two-factor authentication and one-use recovery codes
  • Rate limits on registration, login and recovery
  • Signed and idempotent Stripe webhook processing
  • Administrative audit records
  • Short-domain activation lock

Operational security

Protection continues beyond sign-in.

Infrastructure

Production secrets and customer data are stored outside the public web root with restricted access, health checks and backup procedures.

Mail security

SPF, DKIM, DMARC, TLS, spam controls and outbound abuse limits protect the hosted mail service and its reputation.

Account control

Customers can use authenticator-based two-factor protection, separate mailbox passwords and verified recovery workflows.

Responsible reporting

Security concerns can be reported to security@privateaccess.space.