Security
Defense-in-Depth by Design
We build security into every layer: authentication, authorization, input validation, storage, monitoring, and incident response.
Last updated:
Overview
Security standards
Algovex is secured end-to-end across the following domains:
- TLS 1.2+: Transit security for all client-server communication.
- scrypt: Memory-hard password hashing.
- Rate limits: Brute-force defense on all authentication endpoints.
- CSP: Content Security Policy headers to mitigate XSS.
- Audit logs: Full traceability for sensitive actions.
- GDPR: Privacy controls aligned with EU regulation.
Certifications
Certifications & compliance
Algovex is published by Tacticx Development, part of the tacticx Group. The group's information security management system is certified to ISO/IEC 27001 by TÜV NORD CERT, with recertification completed in 2026.
- ISO/IEC 27001: the international standard for managing information security (ISMS), independently audited and certified by TÜV NORD CERT.
- GDPR: privacy controls aligned with EU regulation (see the Overview above).
The certificate is held by the tacticx organization and covers its information security management. Certificate details are published at tacticx.de and tacticx.dev; the certificate number is available on request via [email protected].
Authentication
Implemented protections
- Cookie-only auth: access + refresh tokens are stored as HttpOnly cookies (no token JSON responses).
- CSRF mitigation: same-origin enforcement via Origin/Referer/Sec-Fetch-Site for state-changing requests.
- CSP rollout: CSP report endpoint enabled; enforcement can be activated after monitoring.
- Session hardening: session tokens stored as SHA-256 hashes in the database; refresh token rotation is atomic.
- Rate limits on login/refresh/OAuth init+callback; auth responses are no-store.
Secure by default
Headers & browser hardening
Modern security headers, strict cookie settings, and least-privilege patterns are applied across the app.
- CSP (report-only rollout)
- X-Frame-Options / frame-ancestors
- NoSniff + Referrer Policy
- Safer image remote allowlisting
Abuse & bot resistance
Rate limits & anomaly detection
We mitigate brute-force and automation with rate limits and operational safeguards at critical entry points.
- IP + identifier rate limits
- Uniform error handling to prevent information leakage
- Session invalidation on bans
- Telemetry for anomalous spikes
Injection hardening
Input validation & sanitization
User content is treated as untrusted by default and sanitized/validated before it can reach sensitive sinks.
- Stored-XSS mitigation
- Upload MIME + magic-byte checks
- Safe filenames + extensions
- No raw HTML rendering by default
Operational security
Auditability & recovery
Security includes the operating model: traceability, auditability, and safe incident response.
- Audit logs for sensitive actions
- Structured error events
- Backups + recovery planning
- Key rotation readiness
Data flow
How your data flows through Algovex
- Authenticate: Sessions are validated server-side and protected with strict cookie settings and rate-limited authentication flows.
- Authorize: Access to sensitive actions is gated by role checks, ownership rules, and consistent server-side authorization.
- Validate: File uploads and inputs are validated defensively (MIME checks, magic bytes for images, safe filenames) to reduce injection risks.
- Observe: We keep structured logs and audit trails for critical workflows to support incident response and forensic analysis.
- Recover: Backups, key rotation, and operational controls are designed to minimize blast radius and restore service quickly.
Disclosure
Responsible disclosure
Found a vulnerability? Report it to [email protected]. We aim to acknowledge reports within 24 hours and prioritize fixes quickly based on severity.
No legal action against good-faith security researchers.