Security
Security at TechLogHub
We build with security at the core — from transport encryption to access controls and responsible disclosure.
Infrastructure
- Hosted on secure cloud infrastructure with encryption at rest managed by the cloud provider.
- All traffic served exclusively over HTTPS / TLS 1.2+ — plain HTTP is rejected.
- Database backups run on a regular schedule and are stored encrypted.
Authentication
- Passwords are hashed using bcrypt — never stored in plain text.
- Sessions are managed with short-lived, signed JWT tokens that expire automatically.
- CSRF protection is applied to all state-changing requests.
Access Control
- Role-based permissions control what each user can see and modify.
- Admin and moderation access is restricted to verified team members only.
- API endpoints validate authentication and authorisation on every request.
Data & Payments
- User data is stored in MongoDB with encryption at rest provided by the cloud host.
- Payment processing is handled entirely by Razorpay — we never receive or store card or bank details.
- We do not sell or share personal data with third parties for marketing purposes.
Responsible Disclosure
If you discover a security vulnerability on TechLogHub, please report it to us before disclosing it publicly so we have the opportunity to fix it. Email your findings to [email protected] with a clear description and reproduction steps.
- We will acknowledge your report within 5 business days.
- We ask that you allow us 90 days to investigate and deploy a fix before any public disclosure.
- We are grateful for responsible researchers and will credit you (if you wish) after the issue is resolved.


