§ 04 · Security
Trust & protection
Security designed into the foundation.
Baalvion treats security, isolation, and accountability as architecture — built in from the first commit, not added after the fact.
How we protect the platform
Passwordless authentication
There are no stored passwords to steal. Identity is verified with short-lived, one-time email codes and signed sessions.
Encryption in transit
All traffic is served over HTTPS with HSTS, and sensitive data is encrypted at rest.
Tenant isolation
Each organisation’s data is isolated with row-level controls so tenants, currencies, and jurisdictions stay separated.
Least-privilege access
Staff and services hold only the access their role requires, with sensitive actions captured in an audit log.
Abuse prevention
Authentication endpoints are rate-limited and protected with human-verification to stop automated attacks.
Hardened delivery edge
Strict security headers, a content-security policy, and bot mitigation are enforced at the edge.
Our commitments to you
Privacy and protection, by default.
- We protect your privacy and never sell your personal data.
- We collect the minimum data needed to operate your account.
- We are transparent about every email we send.
- We respond to security reports promptly and act on them.
Responsible disclosure
Found something? Tell us.
If you believe you have found a security vulnerability, please report it privately to security@baalvion.com. We investigate every report and will not pursue good-faith research conducted under this policy.