Last updated: 28 July 2026
Security
A factual summary of security measures evidenced in the current codebase, not a certification or guarantee.
Verified foundations
- Tenant IDs and tenant-scoped repository queries separate instructor workspaces.
- Argon2 password hashing; short-lived JWT access tokens; hashed, rotating refresh tokens.
- Private object storage with expiring signed upload/download links and unguessable hashed public-share tokens.
- TLS termination and security headers in the documented reverse-proxy configuration.
- Signature verification and idempotency records for Stripe webhooks.
- Audit records for critical authentication events and operational records for communications/billing.
Important limitations
No system is perfectly secure. The repository does not prove production hosting region, backup design, encryption-at-rest/key ownership, penetration testing, certification, formal access reviews, incident-response timing or complete sensitive-data audit coverage. These controls require production verification and documentation.
Report a security issue
Email support@drivefino.com with a minimal description. Do not include passwords, live tokens, payment-card details, medical records or unnecessary personal data. Do not access, alter or download other people’s data while testing.
How reports are handled
Drivefino reviews good-faith security reports and may request further information through an appropriate channel. No response-time, reward or bug-bounty promise is made. Testing must remain lawful and must not disrupt the service or compromise another person’s data.