Overview
Only controls visible in and supported by the current production application implementation are described here.
- Tenant-scoped authorisation for user data.
- Secure password hashing.
- TLS protection for production web traffic.
- Secure, HTTP-only session cookies and strict session handling.
- Protected credential and application-data storage outside the public website directory.
- Origin validation, CSRF protection for authenticated state-changing requests and request throttling.
- Restricted administrator authentication.
Customer responsibilities
Customers should use unique credentials, restrict administrator access, keep recovery details current, remove former-user access, maintain camera and network security, and report suspected compromise promptly.
Security vulnerability reporting
Report suspected vulnerabilities to manideepx@gmail.com. Include the affected page or component, a description, reproduction steps, potential impact, supporting material where safe and reporter contact information.
Reporters must not access unrelated customer data, disrupt the service, conduct denial-of-service testing, use social engineering or publicly disclose an issue before TRL AI has had a reasonable opportunity to investigate.
Use the dedicated security-report route.