BuyerProtectionAustralia

Security

Test the boundary. Do not trust a screenshot.

Review signed access, narrow data fields and fail-closed decisions now. The assurance contract binds every assessment to the exact release candidate.

Product reviewPublic controls + walkthrough
Independent assuranceCandidate-bound review
Candidatebpsac_16bfaa72af9f11af576a92e9
Transport

HTTPS and HSTS

Browser and API traffic is forced onto secure transport.

Private access

Signed, expiring order links

A guessed order number does not open a private record.

Commerce

Verified Shopify deliveries

HMAC, store authority and delivery identity are checked before an event is accepted.

Merchant access

Tenant, principal and role bound

Inactive merchants lose every session. Read-only users can inspect but cannot change orders, evidence, integrations or billing.

Implemented

Same-origin mutation checks

Authenticated writes and one-time-link consumption are rejected when the request origin cannot be verified.

Implemented

Trusted proxy boundary

Forwarded client and protocol headers are accepted only from configured proxy ranges; blanket trust ranges are rejected.

Implemented

Shared anonymous-ingress limits

A distributed Redis-backed limiter is active; public events, authentication and Item Check use bounded quotas.

Implemented

Non-root application runtime

The application runs under a dedicated non-root user.

Recovery review

Backup and clean restore

Persistent backups are encrypted. The institution pack binds off-site copy and timed clean-room recovery evidence to the deployment under review.

Operator access

Authenticated actions with an audit chain

Privileged routes require an admin credential and append an access event.

Assurance process

Candidate-bound independent assessment

Assessor identity, findings and signed retest records attach to the exact release candidate reviewed.

Responsible disclosure

Found a weakness? Use the security route.

Include the affected path, impact, reproduction steps and a safe contact. Do not access customer records or degrade the service.

Submit a security report →