Market MiraeMarket Mirae
// Security Policy

Security Policy

Last updated: 1 March 2026  ·  Questions or reports: security@marketmirae.com

Our Security Commitment

Market Mirae is committed to protecting the confidentiality, integrity, and availability of user data and the platform as a whole. This policy describes our current technical and operational security controls and how to report vulnerabilities.

Important: This document reflects reasonable care applied to a pre-launch product. It should not be treated as an audit report, third-party attestation, or legal warranty. Controls are continuously reviewed and improved.

Authentication Security

  • Passwords are hashed using bcrypt with a unique per-user salt (work factor ≥ 12).
  • Session tokens are cryptographically random (UUID4 hex, 256 bits), stored in HttpOnly, Secure, SameSite=Lax cookies.
  • Sessions expire after 7 days of inactivity and are invalidated immediately on password reset or logout.
  • Google OAuth login uses Emergent Auth, which provides PKCE, state nonce, and token validation.
  • Login attempts are rate-limited per IP and per email with exponential backoff.
  • CAPTCHA challenge (server-side math puzzle) activates after 3 consecutive failed login attempts.
  • Brute-force protection is enforced via Upstash Redis with independent key namespaces per IP, email, and session.

Two-Factor Authentication (2FA)

  • TOTP-based 2FA (RFC 6238, SHA-1, 30-second window) is available for all accounts.
  • Compatible with Microsoft Authenticator, Google Authenticator, Authy, 1Password, and any standard TOTP app.
  • TOTP secrets are encrypted with AES-256-GCM before storage. The encryption key is held only in the server environment and is never sent to the client.
  • 8 single-use recovery codes are issued at enrollment; each is bcrypt-hashed before storage and cleared on use.
  • Trusted-device cookies (30-day TTL) skip the TOTP challenge for verified devices after initial 2FA verification.
  • Recovery code and TOTP verification attempts are rate-limited (5 per 5 minutes).
  • 2FA is mandatory for all admin accounts. Admins cannot access admin functions without 2FA enabled.
  • Disabling 2FA, regenerating recovery codes, and sensitive account changes require step-up authentication (password re-entry + TOTP).

Session Management

  • Users can view all active sessions with browser, OS, IP address, and creation time.
  • Individual sessions can be revoked from Account → Security.
  • The current session is clearly highlighted and protected from accidental self-revocation.
  • "Sign out all other devices" is available and requires step-up authentication.
  • A security event log shows the last 50 security actions with timestamp, IP, and device info.

Transport & Data Security

  • All traffic is encrypted in transit with TLS 1.2+ enforced by the Kubernetes ingress.
  • API routes are prefixed under /api and separated from static frontend delivery.
  • CORS policy allows only the designated application origin.
  • No sensitive data (passwords, TOTP secrets, session tokens) is logged at any severity level.

Image Upload Security

  • Uploaded images are validated by magic bytes, MIME type, and file-extension allowlist (JPEG, PNG, WebP only).
  • SVG, GIF, BMP, TIFF, and all non-image types are rejected.
  • Images are re-encoded server-side with Pillow to eliminate embedded payloads.
  • EXIF metadata is stripped from all images before processing.
  • ClamAV malware scanning is applied to each uploaded file.
  • File size is capped. Originals are not persistently stored after processing.

Security Notifications

Security email notifications are sent for the following events:

  • 2FA enabled or disabled
  • Recovery codes regenerated
  • New device login detected
  • Session revoked
  • Password changed or reset

All notifications include the timestamp, source IP address, and device/browser details. Notifications are delivered via Resend and are sent from security@marketmirae.com.

Rate Limiting & Abuse Prevention

  • Login: 5 attempts per IP/email combo per window; 3 failures trigger CAPTCHA.
  • 2FA verification: 5 attempts per 5 minutes per IP.
  • Step-up auth: 5 attempts per 5 minutes per user.
  • Password reset: 3 tokens per hour per email; tokens expire in 10 minutes and are single-use.
  • Rate-limiting state is stored in Upstash Redis and survives server restarts.

Admin Security

  • Admin access requires a separate two-step unlock: environment code + admin TOTP secret.
  • All admin accounts must have user-account 2FA enabled to access any admin functionality.
  • Admin sessions are separate cookies with a shorter TTL than regular user sessions.
  • An optional IP allowlist can restrict admin logins to known IP ranges.
  • All admin actions are written to an audit log (collection: audit_logs).

Data & Infrastructure

  • Application data is stored in MongoDB. Database credentials are environment-only and not hard-coded.
  • Database backups use mongodump with gzip compression. Backup integrity is verified by test-restore to a clean environment and document-count validation.
  • All production secrets (session signing keys, TOTP encryption key, API keys) are held in environment variables provisioned by the hosting platform — never committed to source control.

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. Please report issues to security@marketmirae.com. Include as much detail as possible: affected endpoint, reproduction steps, potential impact, and any proof-of-concept.

We will acknowledge your report within 72 hours and aim to resolve critical issues within 14 days. Please do not publish details publicly until we have had a reasonable opportunity to respond and remediate.

We do not currently operate a formal bug-bounty program but will acknowledge researchers publicly with their consent.

Policy Updates

This Security Policy may be updated as controls evolve. Material changes will be reflected in the "Last updated" date at the top of this page. Continued use of the service after a policy update constitutes acceptance of the revised controls.

We use one essential cookie (session_token) to keep you logged in. No tracking or advertising cookies. Privacy Policy