GIRVO SECURITY
Security centre
Security controls implemented in the product, with no inflated claims.
Operational draft · last updated 26 August 2026Implemented
- Independent GIRVO accounts, one-time email verification during registration, hardened password storage, protected sessions, and server-side authorization.
- Same-origin protection on write requests and HTTPS-only external links.
- Access-controlled private messages; message text is not exposed in notifications or public profiles.
- Private R2 file storage with ownership checks and protected downloads.
- Owner-only queues and audit records for sensitive decisions.
Before public launch
Complete an independent penetration test, restore drill, load test, incident-response runbook, and legal privacy review. These activities are not claimed as complete.
Reporting
A dedicated security contact and disclosure process will be published before access is widened.