1. Security Controls
SiteGuard uses layered access controls, password hashing, session protection, organisation isolation, monitoring logs and secure production configuration.
2. Monitoring Request Protection
Monitoring requests are designed to block private, local, metadata and unsupported destinations and to validate redirects and DNS results.
3. Payment Security
Card data is handled by authorised providers such as an authorised payment provider. SiteGuard should not store full card numbers or security codes.
4. Secrets and Encryption
Production secrets must be stored in protected environment variables or secret-management systems and must not appear in client-side code or logs.
5. Responsible Disclosure
Report vulnerabilities to hello@siteguard.store with subject “Security Report”. Do not access or disclose data beyond what is necessary to demonstrate an issue.