How we protect accounts, payments, and platform data. Practices below are a draft summary — confirm exact certifications before publishing.
Password hashing, optional 2-factor via the sign-in security code step, session monitoring, and device sign-out controls.
Data encrypted in transit (TLS) and at rest for account, payment, and Essence Credit records.
Payments processed via PCI-compliant providers; StackGrasp does not store raw card numbers.
All submitted courses pass through the moderation queue before publishing, with reporting for post-publish issues.
Access controls, audit logging, and monitoring across production systems.
On-chain components (credentials, bounties) are treated as unaudited until formally reviewed — see the developer handoff notes.
Found a security issue? Email security@stackgrasp.example (placeholder — confirm real contact before publishing). Please don't test against production without permission.