Security is a core priority at S.S.S. Corporation. We are committed to protecting the data of our users, customers, and partners. This page outlines our security practices and how to responsibly report vulnerabilities.
All data transmitted to and from our services is encrypted using TLS/SSL protocols.
Admin access requires email + password combined with OTP-based two-factor authentication.
All passwords are hashed using Argon2id. Sensitive data is encrypted at rest.
Login attempts are rate-limited per IP and account to prevent brute-force attacks.
All user inputs are sanitised and validated to prevent SQL injection and XSS attacks.
All forms include CSRF tokens to prevent cross-site request forgery attacks.
Our web server implements the following HTTP security headers on all responses:
We follow the principle of least privilege across all systems:
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue on any of our websites or services, we ask that you:
We do not operate a bug bounty programme at this time, but we genuinely appreciate responsible researchers who help us improve our security posture.
Report it privately and we'll investigate promptly. Please include details of the vulnerability, affected URL, and steps to reproduce.
business@ssscorp.inThis security policy covers: