ENTERPRISE CRYPTOGRAPHIC STANDARDS

Security & Infrastructure

Engineered from first principles with institutional defense-in-depth, cryptographic identity verification, and immutable double-entry ledger safety.

1. Salted Bcrypt 12-Round Password Hashing

All user passwords are encrypted server-side using 12 rounds of bcrypt salt before database insertion. Plaintext passwords are never logged, transmitted, or accessible to platform administrators.

2. Purpose-Bound Cryptographic OTP Engine

Email verification and password recovery use cryptographically random 6-digit OTPs hashed with distinct purpose salts, 10-minute expiry, and a strict 5-attempt rate limit.

3. HTTP-Only Secure JWT Session Cookies

Authenticated user, admin, and influencer sessions utilize signed JSON Web Tokens (JWT) stored in HTTP-only, SameSite=Lax cookies, safeguarding sessions against Cross-Site Scripting (XSS) extraction.

4. Server-Side Role-Based Middleware Guards

Every protected route (/admin/*, /influencer/*, /dashboard, /wallet) is verified at the server edge using Next.js middleware and route handlers, preventing unauthorized tampering or direct URL bypass.

5. ACID-Compliant Atomic Financial Transactions

All wallet operations (deposits, plan subscriptions, daily profit accruals, principal releases, and withdrawals) are wrapped in atomic database transactions, preventing race conditions or double credits.

6. HMAC-SHA256 Payment Webhook Verification

Inbound payment notifications from payment gateways (EasyPaisa / JazzCash) are cryptographically validated against shared secrets via HMAC-SHA256 before crediting user wallet balances.

7. Idempotent Daily Profit Accrual

Daily yield engine enforces composite database uniqueness on (investmentId, accrualDate), ensuring each active investment receives its calculated daily distribution exactly once per Pakistan calendar day.

8. Non-Cascading Audit Trail & Immutable Ledger

Financial records (deposits, withdrawals, investments, transactions, commissions) are strictly isolated with Restrict delete constraints, preserving complete audit trails for lifetime institutional accountability.

Vulnerability Disclosure & Security Reports

We welcome responsible vulnerability disclosures from security researchers. If you identify an issue, report it directly to our security engineering team.

Report Security Issue