HTTPS and TLS
Public traffic is served over HTTPS. HTTP Strict Transport Security is enabled so browsers keep using TLS.
GlobalPass+ protects candidate accounts, assessments, results and certificates with TLS, hashed passwords, session controls, role checks, signed credentials and monitored backups.
Public traffic is served over HTTPS. HTTP Strict Transport Security is enabled so browsers keep using TLS.
Passwords are hashed with Argon2. Privileged accounts use multi-factor authentication. Sessions use HTTP-only cookies, CSRF protection and revocation.
Candidates, organisations, reviewers and operators see only the routes their role allows. Admin actions are authenticated and recorded.
Assessment responses, identity data and credentials are stored in private services. Public verification exposes only the fields listed on the verify page.
Application secrets, signing keys and payment credentials are mounted as files, not committed to source. Stripe payment confirmations are verified before assessment access is granted.
Issued certificates carry a unique ID, QR code and cryptographic signature so anyone can check active, expired, suspended or revoked status.
Services run in non-root containers with internal networks, resource limits, health checks and audit logs. Monitoring alerts on health and error signals.
Encrypted production backups are taken on the privately controlled host. Restore rehearsal is part of the release process before schema changes.
Send a clear description, affected URL, reproduction steps and impact to security@globalpassplus.com. Do not access other people’s data, degrade service, or publicly disclose an unresolved issue.
We acknowledge a valid report within two business days, investigate in good faith and coordinate remediation. Never include live credentials, identity documents or candidate data in ordinary email.