Security at LivraOne
Last updated July 19, 2026
Tenant isolation
Workspace membership and server-side permission policies restrict every request. Transactional data is designed for PostgreSQL row-level security as an additional tenant boundary.
Account protection
Passwords use a memory-hard hash, sessions are revocable and rotated, password recovery uses time-limited links, and privileged actions are recorded in an audit trail.
Files and infrastructure
Media is stored in restricted object storage with short-lived signed access. The application origin is not intended for direct public exposure, and secrets remain outside source control and container images.
Report a concern
Please send suspected vulnerabilities privately to security@livraone.com. Do not include sensitive customer data in an initial report.
