Security

Security at GlobalPass+

GlobalPass+ protects candidate accounts, assessments, results and certificates with TLS, hashed passwords, session controls, role checks, signed credentials and monitored backups.

Transport

HTTPS and TLS

Public traffic is served over HTTPS. HTTP Strict Transport Security is enabled so browsers keep using TLS.

Identity

Authentication

Passwords are hashed with Argon2. Privileged accounts use multi-factor authentication. Sessions use HTTP-only cookies, CSRF protection and revocation.

Access

Role-based controls

Candidates, organisations, reviewers and operators see only the routes their role allows. Admin actions are authenticated and recorded.

Data

Private storage

Assessment responses, identity data and credentials are stored in private services. Public verification exposes only the fields listed on the verify page.

Secrets

Protected credentials

Application secrets, signing keys and payment credentials are mounted as files, not committed to source. Stripe payment confirmations are verified before assessment access is granted.

Certificates

Signed credentials

Issued certificates carry a unique ID, QR code and cryptographic signature so anyone can check active, expired, suspended or revoked status.

Operations

Isolation and monitoring

Services run in non-root containers with internal networks, resource limits, health checks and audit logs. Monitoring alerts on health and error signals.

Recovery

Backups

Encrypted production backups are taken on the privately controlled host. Restore rehearsal is part of the release process before schema changes.

Responsible disclosure

Report a vulnerability

Send a clear description, affected URL, reproduction steps and impact to security@globalpassplus.com. Do not access other people’s data, degrade service, or publicly disclose an unresolved issue.

We acknowledge a valid report within two business days, investigate in good faith and coordinate remediation. Never include live credentials, identity documents or candidate data in ordinary email.