1. Our approach
VaultX uses layered administrative and technical controls designed to reduce unauthorised access, misuse, loss, and disclosure. No service can guarantee absolute security, and controls are reviewed as the product and threat environment change.
2. Account safeguards
- Passwords require at least 12 characters.
- Sign-in and sign-up endpoints use rate limits.
- Sessions have bounded lifetimes and framework-managed cookies.
- OAuth state is stored server-side, provider tokens are encrypted at rest, and account linking requires matching email addresses.
- Google and Microsoft sign-in activate only when deployment credentials are present.
3. Operational safeguards
Production readiness includes HTTPS, managed secrets, least-privilege access, encrypted provider connections, secure backups, recovery testing, dependency updates, protective response headers, logging, alerting, and an incident-response process. Payment webhooks and uploads must remain disabled until signature verification, validation, scanning, reconciliation, and monitoring are tested.
4. Report a vulnerability
Email security@vaultx.hair with the affected page, a concise description, safe reproduction steps, and potential impact. The mailbox must be provisioned before public launch.
Please do not access another person’s data, disrupt the service, run high-volume automated tests, upload malware, or disclose an unresolved issue publicly. VaultX does not currently operate a paid bug-bounty programme.
5. Protect your account
Use a unique password, secure your email account, sign out on shared devices, and contact us about unexpected account activity. Never send a password, one-time code, complete payment credential, or secret key by email. See the Privacy Policy for information about personal data.