Security

Security practices and responsible disclosure

Security is a core design principle of the Singulr platform. This page summarises the security controls we apply to protect your data and describes how to responsibly report potential vulnerabilities.

Platform Security Controls

Multi-Factor Authentication

TOTP-based MFA (RFC 6238) with strict monotonic counters is available for all accounts. Privileged actions require MFA within a 10-minute freshness window. Google SSO is also supported for federated identity.

Password Security

Passwords are hashed using bcrypt with a work factor appropriate to modern hardware. Plaintext passwords are never stored or logged. Password reset flows use time-limited, single-use tokens.

Session Management

Sessions use HMAC-signed tokens with epoch-based invalidation, enabling immediate revocation across all active sessions. Session cookies are HttpOnly, Secure, and SameSite-strict.

Audit Logging

All authentication events, administrative actions, and security-relevant mutations are recorded in a tamper-evident audit log retained for 12 months. Logs are available to workspace owners.

Multi-Tenant Isolation

Each workspace is logically isolated at the data layer. All API endpoints enforce ownership and membership checks server-side before returning or modifying data. Cross-tenant data access is prevented by design.

Rate Limiting

Authentication endpoints are rate-limited to prevent brute-force attacks. Account lockout policies are applied after repeated failed authentication attempts.

Data in Transit and at Rest

All data in transit is encrypted via TLS 1.2+ (managed by our hosting provider). Database backups are encrypted at rest. Sensitive fields such as TOTP secrets are stored encrypted.

Role-Based Access Control

The platform enforces tiered role-based access control. Administrative and other privileged operations are restricted to designated accounts and enforced server-side, independent of what the interface displays.

Responsible Disclosure Policy

We welcome security researchers and community members who responsibly investigate and report potential vulnerabilities in the Singulr platform. If you believe you have discovered a security issue, please follow the guidelines below.

How to report

Send a detailed report to security@singulr.com.au. Please include:

Scope

In scope: the Singulr web application at singulr.com.au and its API endpoints. Out of scope: third-party services we depend on (Google, Replit infrastructure), denial-of-service attacks, social engineering, and physical security.

Rules of engagement

Response Commitments

We take all reports seriously. Our target response times are:

Initial acknowledgementWithin 48 hours of receipt
Triage and severity assessmentWithin 5 business days
Remediation of critical and high severity issuesWithin 7 days of confirmed triage
Remediation of medium severity issuesWithin 30 days of confirmed triage
Coordinated disclosure notificationPrior to any public disclosure

While we do not currently operate a formal bug bounty programme, we are grateful for responsible disclosures and will acknowledge researchers who report valid findings (with permission).

Security Contact

Singulr Pty Ltd - Security Team
security@singulr.com.au

For non-security support enquiries, please contact us at accounts@singulr.com.au.

About · Privacy Policy · Terms of Service