Legal

Security

Last updated: July 15, 2026

Infrastructure Security

Cloud Provider

DigitalOcean with SOC 2 and ISO 27001 certified data centers

Network Security

Firewalls restrict access to only necessary ports and services

DDoS Protection

DigitalOcean's network-level DDoS mitigation

Isolated Networks

Redis, PostgreSQL, and application servers in separate network segments

Data Encryption

In Transit

TLS 1.3 with strong cipher suites for all browser and API connections

At Rest

AES-256 encryption on all database volumes and backups

Passwords

Bcrypt hashing with 12 rounds of salting — never stored in plaintext

API Keys

Encrypted at rest; displayed only once at creation time

Authentication & Access Control

Multi-factor authentication (MFA) for all accounts
OAuth 2.0 via Google for secure third-party auth
JWT-based sessions with configurable expiry
RBAC: 5 roles from Platform Admin to Viewer
CSRF protection on all state-changing endpoints
Rate limiting on auth endpoints to prevent brute force

Application Security

Security headers on all responses (HSTS, XSS, CSP)
Input validation and sanitization on all inputs
Parameterized queries to prevent SQL injection
Per-tenant PostgreSQL schemas for data isolation
Regular dependency scanning for CVEs
Content Security Policy to prevent XSS attacks

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. Please email security@sinorai.com.

Acknowledgement within 48 hours
Resolution timeline within 7 days
No legal action for good-faith research
Public credit with your permission

Report a vulnerability

Email: security@sinorai.com