Algovex

Features

Blueprint

Pricing

Blog

Gallery

Tools

Join Waitlist

Join Waitlist

Algovex

Features

Blueprint

Pricing

Blog

Gallery

Tools

Join Waitlist

Join Waitlist

Security

Defense-in-Depth by Design

We build security into every layer: authentication, authorization, input validation, storage, monitoring, and incident response.

Last updated: 2026-05-03

Overview

Security standards

Algovex is secured end-to-end across the following domains:

  • TLS 1.2+: Transit security for all client-server communication.
  • scrypt: Memory-hard password hashing.
  • Rate limits: Brute-force defense on all authentication endpoints.
  • CSP: Content Security Policy headers to mitigate XSS.
  • Audit logs: Full traceability for sensitive actions.
  • GDPR: Privacy controls aligned with EU regulation.

Certifications

Certifications & compliance

Algovex is published by Tacticx Development, part of the tacticx Group. The group's information security management system is certified to ISO/IEC 27001 by TÜV NORD CERT, with recertification completed in 2026.

  • ISO/IEC 27001: the international standard for managing information security (ISMS), independently audited and certified by TÜV NORD CERT.
  • GDPR: privacy controls aligned with EU regulation (see the Overview above).

The certificate is held by the tacticx organization and covers its information security management. Certificate details are published at tacticx.de and tacticx.dev; the certificate number is available on request via [email protected].

Authentication

Implemented protections

  • Cookie-only auth: access + refresh tokens are stored as HttpOnly cookies (no token JSON responses).
  • CSRF mitigation: same-origin enforcement via Origin/Referer/Sec-Fetch-Site for state-changing requests.
  • CSP rollout: CSP report endpoint enabled; enforcement can be activated after monitoring.
  • Session hardening: session tokens stored as SHA-256 hashes in the database; refresh token rotation is atomic.
  • Rate limits on login/refresh/OAuth init+callback; auth responses are no-store.

Secure by default

Headers & browser hardening

Modern security headers, strict cookie settings, and least-privilege patterns are applied across the app.

  • CSP (report-only rollout)
  • X-Frame-Options / frame-ancestors
  • NoSniff + Referrer Policy
  • Safer image remote allowlisting

Abuse & bot resistance

Rate limits & anomaly detection

We mitigate brute-force and automation with rate limits and operational safeguards at critical entry points.

  • IP + identifier rate limits
  • Uniform error handling to prevent information leakage
  • Session invalidation on bans
  • Telemetry for anomalous spikes

Injection hardening

Input validation & sanitization

User content is treated as untrusted by default and sanitized/validated before it can reach sensitive sinks.

  • Stored-XSS mitigation
  • Upload MIME + magic-byte checks
  • Safe filenames + extensions
  • No raw HTML rendering by default

Operational security

Auditability & recovery

Security includes the operating model: traceability, auditability, and safe incident response.

  • Audit logs for sensitive actions
  • Structured error events
  • Backups + recovery planning
  • Key rotation readiness

Data flow

How your data flows through Algovex

  • Authenticate: Sessions are validated server-side and protected with strict cookie settings and rate-limited authentication flows.
  • Authorize: Access to sensitive actions is gated by role checks, ownership rules, and consistent server-side authorization.
  • Validate: File uploads and inputs are validated defensively (MIME checks, magic bytes for images, safe filenames) to reduce injection risks.
  • Observe: We keep structured logs and audit trails for critical workflows to support incident response and forensic analysis.
  • Recover: Backups, key rotation, and operational controls are designed to minimize blast radius and restore service quickly.

Disclosure

Responsible disclosure

Found a vulnerability? Report it to [email protected]. We aim to acknowledge reports within 24 hours and prioritize fixes quickly based on severity.

No legal action against good-faith security researchers.

Product

FeaturesMarketplaceNode LibraryUse casesPricing

Company

AboutContactChangelog

Resources

Free toolsBlogGalleryHelp & SupportRoadmapFeature Request

Legal

PrivacyTermsImprintCookiesCookie SettingsDisclaimer

Policies

Refund PolicyCancellationVerträge kündigenSecurityData sourcesAccessibility
© 2026 tacticx Development GmbH · All rights reserved.