Skip to main content

Last updated: 28 July 2026

Security

A factual summary of security measures evidenced in the current codebase, not a certification or guarantee.

Early-access notice. Drivefino is currently in an early-access validation stage. Product features and these terms may develop as the service is tested and improved.

Verified foundations

  • Tenant IDs and tenant-scoped repository queries separate instructor workspaces.
  • Argon2 password hashing; short-lived JWT access tokens; hashed, rotating refresh tokens.
  • Private object storage with expiring signed upload/download links and unguessable hashed public-share tokens.
  • TLS termination and security headers in the documented reverse-proxy configuration.
  • Signature verification and idempotency records for Stripe webhooks.
  • Audit records for critical authentication events and operational records for communications/billing.

Important limitations

No system is perfectly secure. The repository does not prove production hosting region, backup design, encryption-at-rest/key ownership, penetration testing, certification, formal access reviews, incident-response timing or complete sensitive-data audit coverage. These controls require production verification and documentation.

Report a security issue

Email support@drivefino.com with a minimal description. Do not include passwords, live tokens, payment-card details, medical records or unnecessary personal data. Do not access, alter or download other people’s data while testing.

How reports are handled

Drivefino reviews good-faith security reports and may request further information through an appropriate channel. No response-time, reward or bug-bounty promise is made. Testing must remain lawful and must not disrupt the service or compromise another person’s data.