Security and trust

Security controls for assessment and identity data.

Security controls are designed around least privilege, traceable decisions, private storage and limited public disclosure. This overview describes the current application design and the controls required before commercial launch.

Identity

Account protection

Argon2 password hashing, HTTP-only secure sessions, CSRF protection, session revocation and MFA for privileged users.

Data

Private by default

Databases, queues, monitoring and candidate files are not published directly. Permission-checked routes and short-lived sharing links control access.

Credentials

Tamper evidence

Signed credential payloads, unique IDs, status history and QR verification make revocation and signature state visible.

Operations

Constrained services

Non-root containers, internal service networks, resource limits, health checks, log rotation and controlled releases reduce the impact of a single fault.

Recovery

Backups outside the VPS

Production acceptance requires encrypted off-server backups, retention controls and restore rehearsal. A copy on the same server is not treated as a backup.

Decisions

Human review

Browser and integrity events create review evidence, not automatic accusations. Decisions, reasons and appeals remain auditable.

Responsible disclosure

Report a vulnerability

Send a clear description, affected URL, reproduction steps and impact to security@globalpassplus.com. Do not access or alter other people’s data, degrade service, perform social engineering or publicly disclose an unresolved issue.

We will acknowledge a valid report within two business days, preserve confidentiality, investigate in good faith and coordinate remediation and disclosure. Never include live credentials, identity documents or candidate data in an ordinary email.

Read the privacy noticeReview accessibility and accommodations →