Access controls
Passwordless session tokens are signed, HTTP-only, same-site, and secure in production. Every organization-owned query includes an organization predicate, and PostgreSQL row-level security provides defense in depth.
Application security
- Origin checks and CSRF-resistant same-site flows
- Rate-limit integration points and no-store account responses
- Server-only secrets with startup validation
- Content Security Policy and restrictive browser permissions
- Webhook signature verification and idempotent event storage
Operations
Source failures, stale feeds, schema warnings, missing evidence, date anomalies, delivery retries, bounces, and dead letters feed a protected health endpoint and daily summary.
Report an issue
Security reports: security@regchangenow.com. Do not include live credentials or confidential customer data in an initial message.