Production secrets and customer data are stored outside the public web root with restricted access, health checks and backup procedures.
Security
Account protection at every stage.
Security is treated as an operational process covering registration, authentication, recovery, billing, provisioning and mail delivery—not as a single marketing feature.
Account safeguards
These controls are built into the account service and covered by automated tests.
- Argon2id password hashing
- HTTP-only, same-site session cookies
- CSRF protection on state-changing forms
- Time-limited, one-use verification and reset tokens
- Authenticator-based two-factor authentication and one-use recovery codes
- Rate limits on registration, login and recovery
- Signed and idempotent Stripe webhook processing
- Administrative audit records
- Short-domain activation lock
Operational security
Protection continues beyond sign-in.
SPF, DKIM, DMARC, TLS, spam controls and outbound abuse limits protect the hosted mail service and its reputation. PrivateAccess encrypted viewing links apply only to messages sent from PrivateAccess Webmail; desktop and mobile mail applications use conventional email delivery.
Customers use one unified password with authenticator-based two-factor protection and verified recovery workflows.
Responsible reporting
Security concerns can be reported to security@privateaccess.space.
