Security

Security at TechLogHub

We build with security at the core — from transport encryption to access controls and responsible disclosure.

Infrastructure

  • Hosted on secure cloud infrastructure with encryption at rest managed by the cloud provider.
  • All traffic served exclusively over HTTPS / TLS 1.2+ — plain HTTP is rejected.
  • Database backups run on a regular schedule and are stored encrypted.

Authentication

  • Passwords are hashed using bcrypt — never stored in plain text.
  • Sessions are managed with short-lived, signed JWT tokens that expire automatically.
  • CSRF protection is applied to all state-changing requests.

Access Control

  • Role-based permissions control what each user can see and modify.
  • Admin and moderation access is restricted to verified team members only.
  • API endpoints validate authentication and authorisation on every request.

Data & Payments

  • User data is stored in MongoDB with encryption at rest provided by the cloud host.
  • Payment processing is handled entirely by Razorpay — we never receive or store card or bank details.
  • We do not sell or share personal data with third parties for marketing purposes.

Responsible Disclosure

If you discover a security vulnerability on TechLogHub, please report it to us before disclosing it publicly so we have the opportunity to fix it. Email your findings to [email protected] with a clear description and reproduction steps.

  • We will acknowledge your report within 5 business days.
  • We ask that you allow us 90 days to investigate and deploy a fix before any public disclosure.
  • We are grateful for responsible researchers and will credit you (if you wish) after the issue is resolved.