Security
Security practices and responsible disclosure
Security is a core design principle of the Singulr platform. This page summarises the security controls we apply to protect your data and describes how to responsibly report potential vulnerabilities.
Platform Security Controls
Multi-Factor Authentication
TOTP-based MFA (RFC 6238) with strict monotonic counters is available for all accounts. Privileged actions require MFA within a 10-minute freshness window. Google SSO is also supported for federated identity.
Password Security
Passwords are hashed using bcrypt with a work factor appropriate to modern hardware. Plaintext passwords are never stored or logged. Password reset flows use time-limited, single-use tokens.
Session Management
Sessions use HMAC-signed tokens with epoch-based invalidation, enabling immediate revocation across all active sessions. Session cookies are HttpOnly, Secure, and SameSite-strict.
Audit Logging
All authentication events, administrative actions, and security-relevant mutations are recorded in a tamper-evident audit log retained for 12 months. Logs are available to workspace owners.
Multi-Tenant Isolation
Each workspace is logically isolated at the data layer. All API endpoints enforce ownership and membership checks server-side before returning or modifying data. Cross-tenant data access is prevented by design.
Rate Limiting
Authentication endpoints are rate-limited to prevent brute-force attacks. Account lockout policies are applied after repeated failed authentication attempts.
Data in Transit and at Rest
All data in transit is encrypted via TLS 1.2+ (managed by our hosting provider). Database backups are encrypted at rest. Sensitive fields such as TOTP secrets are stored encrypted.
Role-Based Access Control
The platform enforces tiered role-based access control. Administrative and other privileged operations are restricted to designated accounts and enforced server-side, independent of what the interface displays.
Responsible Disclosure Policy
We welcome security researchers and community members who responsibly investigate and report potential vulnerabilities in the Singulr platform. If you believe you have discovered a security issue, please follow the guidelines below.
How to report
Send a detailed report to security@singulr.com.au. Please include:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce, including any relevant URLs, payloads, or screenshots.
- The affected component or area of the platform.
- Your name or handle if you would like acknowledgement (optional).
Scope
In scope: the Singulr web application at singulr.com.au and its API endpoints. Out of scope: third-party services we depend on (Google, Replit infrastructure), denial-of-service attacks, social engineering, and physical security.
Rules of engagement
- Do not access, modify, or delete data belonging to other users.
- Do not perform testing that degrades the availability of the platform for other users.
- Do not exploit a vulnerability beyond what is necessary to confirm its existence.
- Do not publicly disclose a vulnerability before we have had an opportunity to address it.
Response Commitments
We take all reports seriously. Our target response times are:
| Initial acknowledgement | Within 48 hours of receipt |
| Triage and severity assessment | Within 5 business days |
| Remediation of critical and high severity issues | Within 7 days of confirmed triage |
| Remediation of medium severity issues | Within 30 days of confirmed triage |
| Coordinated disclosure notification | Prior to any public disclosure |
While we do not currently operate a formal bug bounty programme, we are grateful for responsible disclosures and will acknowledge researchers who report valid findings (with permission).
Security Contact
Singulr Pty Ltd - Security Team
security@singulr.com.au
For non-security support enquiries, please contact us at accounts@singulr.com.au.