1. Salted Bcrypt 12-Round Password Hashing
All user passwords are encrypted server-side using 12 rounds of bcrypt salt before database insertion. Plaintext passwords are never logged, transmitted, or accessible to platform administrators.
2. Purpose-Bound Cryptographic OTP Engine
Email verification and password recovery use cryptographically random 6-digit OTPs hashed with distinct purpose salts, 10-minute expiry, and a strict 5-attempt rate limit.
3. HTTP-Only Secure JWT Session Cookies
Authenticated user, admin, and influencer sessions utilize signed JSON Web Tokens (JWT) stored in HTTP-only, SameSite=Lax cookies, safeguarding sessions against Cross-Site Scripting (XSS) extraction.
4. Server-Side Role-Based Middleware Guards
Every protected route (/admin/*, /influencer/*, /dashboard, /wallet) is verified at the server edge using Next.js middleware and route handlers, preventing unauthorized tampering or direct URL bypass.
5. ACID-Compliant Atomic Financial Transactions
All wallet operations (deposits, plan subscriptions, daily profit accruals, principal releases, and withdrawals) are wrapped in atomic database transactions, preventing race conditions or double credits.
6. HMAC-SHA256 Payment Webhook Verification
Inbound payment notifications from payment gateways (EasyPaisa / JazzCash) are cryptographically validated against shared secrets via HMAC-SHA256 before crediting user wallet balances.
7. Idempotent Daily Profit Accrual
Daily yield engine enforces composite database uniqueness on (investmentId, accrualDate), ensuring each active investment receives its calculated daily distribution exactly once per Pakistan calendar day.
8. Non-Cascading Audit Trail & Immutable Ledger
Financial records (deposits, withdrawals, investments, transactions, commissions) are strictly isolated with Restrict delete constraints, preserving complete audit trails for lifetime institutional accountability.
Vulnerability Disclosure & Security Reports
We welcome responsible vulnerability disclosures from security researchers. If you identify an issue, report it directly to our security engineering team.