Skip to content
Baalvion

§ 04 · Security

Trust & protection

Security designed into the foundation.

Baalvion treats security, isolation, and accountability as architecture — built in from the first commit, not added after the fact.

How we protect the platform

Passwordless authentication

There are no stored passwords to steal. Identity is verified with short-lived, one-time email codes and signed sessions.

Encryption in transit

All traffic is served over HTTPS with HSTS, and sensitive data is encrypted at rest.

Tenant isolation

Each organisation’s data is isolated with row-level controls so tenants, currencies, and jurisdictions stay separated.

Least-privilege access

Staff and services hold only the access their role requires, with sensitive actions captured in an audit log.

Abuse prevention

Authentication endpoints are rate-limited and protected with human-verification to stop automated attacks.

Hardened delivery edge

Strict security headers, a content-security policy, and bot mitigation are enforced at the edge.

Our commitments to you

Privacy and protection, by default.

  • We protect your privacy and never sell your personal data.
  • We collect the minimum data needed to operate your account.
  • We are transparent about every email we send.
  • We respond to security reports promptly and act on them.

Responsible disclosure

Found something? Tell us.

If you believe you have found a security vulnerability, please report it privately to security@baalvion.com. We investigate every report and will not pursue good-faith research conducted under this policy.