This page describes what Researchor actually does to protect data. It deliberately separates what is in place today from what is planned, because a security page that blurs the two is worse than none.
In place today
- Transport security. All traffic is served over HTTPS. HTTP Strict Transport Security is set with a two-year max-age and includes subdomains.
- Content-Security-Policy. Every page response carries a CSP restricting where scripts, styles, images, fonts, connections and frames may come from. Framing is denied outright.
- Additional response headers.
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, a referrer policy limiting what we leak to other sites, and a permissions policy disabling camera, microphone, geolocation and browsing-topics access. - No source maps in production, and the server technology header is suppressed.
- Secret handling. Credentials live in environment variables and are never exposed to the browser. Only variables explicitly marked public reach the client.
Planned, not yet in place
The following are part of the build and are not operating today. We list them so you can see what is coming, not to imply it already exists.
- Authentication, session management and password hashing
- Two-factor authentication
- Row-level authorisation so no user can read another user's projects, offers or files
- Encrypted file storage for deliverables and uploads
- Payment tokenisation through our payment providers
- Audit logging of administrative access
- Automated backups and a tested restore procedure
What we do not claim
Researchor holds no security certification. We have not completed a SOC 2 examination, an ISO 27001 certification, a penetration test by a third party, or any equivalent assessment. We are not going to display a badge suggesting otherwise.
We also do not claim end-to-end encryption. Messages and files are protected in transit and at rest by our infrastructure providers, which is not the same thing, and describing it as end-to-end would be false.
Reporting a vulnerability
If you find a security issue, email support@researchor.org.ng with enough detail to reproduce it. Please give us a reasonable opportunity to fix it before disclosing it publicly.
We will not pursue legal action against a researcher who reports a vulnerability in good faith, does not access or modify other users' data, and does not degrade the service.
Breach notification
If a breach occurs that is likely to affect your rights, we will notify you and the data protection authorities concerned within the time the law requires.
Questions about this document go to support@researchor.org.ng, or through the contact form.