Identity
Adaptive password hashes, one-time hashed email tokens, revocable database sessions and secure HttpOnly cookies.
TubeBearSecurityTubeBear uses layered access controls for the public account system, protected operator cockpit, credit ledger and internal production services. No certification is claimed.
Adaptive password hashes, one-time hashed email tokens, revocable database sessions and secure HttpOnly cookies.
CSRF checks, body limits, durable rate limiting, brute-force controls and non-enumerating recovery responses.
Server-side RBAC, separate user ownership checks and an additional perimeter around the operator cockpit.
Integer balances, row locks, immutable transactions, unique idempotency keys and reserve/capture/release semantics.
Account and production services bind to loopback behind TLS termination. Provider secrets remain in protected server environment files.
Additive migrations, disposable-database tests, atomic symlinks, health gates, Nginx validation and rollback.
A formal privacy program, retention schedule, subprocessor register, incident policy, external assessment and organization-wide SSO are not yet published.
Send a concise report with impact and reproduction steps. Do not include third-party personal data.