Account protection
Argon2 password hashing, HTTP-only secure sessions, CSRF protection, session revocation and MFA for privileged users.
Security controls are designed around least privilege, traceable decisions, private storage and limited public disclosure. This overview describes the current application design and the controls required before commercial launch.
Argon2 password hashing, HTTP-only secure sessions, CSRF protection, session revocation and MFA for privileged users.
Databases, queues, monitoring and candidate files are not published directly. Permission-checked routes and short-lived sharing links control access.
Signed credential payloads, unique IDs, status history and QR verification make revocation and signature state visible.
Non-root containers, internal service networks, resource limits, health checks, log rotation and controlled releases reduce the impact of a single fault.
Production acceptance requires encrypted off-server backups, retention controls and restore rehearsal. A copy on the same server is not treated as a backup.
Browser and integrity events create review evidence, not automatic accusations. Decisions, reasons and appeals remain auditable.
Send a clear description, affected URL, reproduction steps and impact to security@globalpassplus.com. Do not access or alter other people’s data, degrade service, perform social engineering or publicly disclose an unresolved issue.
We will acknowledge a valid report within two business days, preserve confidentiality, investigate in good faith and coordinate remediation and disclosure. Never include live credentials, identity documents or candidate data in an ordinary email.