SSL LabsA

TLS 1.2 + 1.3 with forward secrecy (ECDHE). Independently verified by Qualys SSL Labs.

CloudflareActive

DDoS protection, Web Application Firewall, and DNS security for all derail-logic.com domains.

OWASP ASVS81%

OWASP Application Security Verification Standard Level 1 self-assessment. Code-verifiable: 87%.

TurnstileEnabled

Cloudflare Turnstile captcha on all public forms. Privacy-first, no user tracking or data collection.

Password Security

  • Passwords hashed with bcrypt (12 rounds) — never stored in plain text
  • 8–128 character length enforced; bcrypt truncation prevented
  • Account lockout after 5 failed attempts (15-minute cooldown)
  • Password reset tokens: 32-byte random, SHA-256 hashed, 1-hour expiry, single-use
  • Password changes logged to audit trail with IP and user agent

Authentication & Sessions

  • JWT access tokens with 15-minute expiry, HS256 algorithm enforced
  • Refresh token rotation with 7-day lifespan
  • Logout immediately blacklists tokens — cannot be reused
  • Login errors never reveal whether an account exists
  • Multi-tenant isolation: every query scoped to your workspace

API & Network Security

  • CSRF protection on all state-changing operations (X-Requested-With header + Origin check)
  • SSRF protection: outbound requests validated against domain allowlist; internal IPs blocked
  • Rate limiting: 500 requests per minute per IP globally
  • Swagger/API docs restricted to development environment only
  • Helmet.js security headers: CSP, X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy

Infrastructure

  • All data encrypted in transit via TLS 1.2+ (SSL Labs Grade A)
  • Cloudflare DDoS protection and Web Application Firewall
  • Stripe payment processing — PCI DSS Level 1; no card data on our servers
  • OAuth tokens for third-party integrations encrypted at rest
  • Server logs redact PII; no passwords or tokens in logs

OWASP ASVS L1 Assessment

81%

OWASP Application Security Verification Standard (ASVS) Level 1 — the industry standard for web application security. Self-assessed via static code analysis and runtime verification. Code-verifiable subset: 87%.

V2 Authentication92%
V13 API & Web Services88%
V3 Session Management86%
V6 Cryptography86%
V7 Error Handling & Logging86%
V5 Validation & Encoding82%
V14 Configuration82%
V1 Architecture & Design100%
V8 Data Protection78%
V9 Communications80%
V4 Access Control60%
V10 Malicious Code50%
V11 Business Logic60%
V12 Files & Resources57%

Self-assessments are internal engineering tools and do not constitute a formal certification. MartechAI is pursuing independent third-party penetration testing. Questions about our security posture? Contact us.

Ready to see the platform?

Start building campaigns on a platform that takes your data security as seriously as you do.

Get Started FreeTalk to Sales