Security
1. How we protect the service
- Sign-in is verified by one-time code to your email or phone, with optional authenticator and bot protection where configured.
- Browser sessions use short-lived access tokens and HttpOnly refresh cookies that rotate. Reuse of an old refresh token is detected.
- Access is scoped to your workspace. Roles (owner, admin, editor, viewer) limit what each person can do, and folder access can be granted separately.
- Scan records store a salted hash of the IP address, not the raw address.
- The redirect service and public generator are rate limited.
- Card details are handled by Razorpay and are not stored by us.
- Backups and restore procedures are run by the operator, and incident response is documented.
2. Limits
We do not currently claim any third-party security certification. Wi-Fi codes made in the workspace store the network password so they can be shown to you, so use a guest network. Anyone who can read a Wi-Fi QR image can recover its password.
3. Report a vulnerability
Email support@luvox.in with details and steps to reproduce. Please do not access other people's data, disrupt the service or publish details before we respond. We will acknowledge reports and keep you updated.