Skip to content

Security: Jeevan-ZGDX/CP-project

Security

SECURITY.md

Refresh-token storage

Refresh tokens are bearer credentials and must never be stored in plaintext. The API stores SHA-256 digests in refresh_tokens.token_hash and hashes incoming tokens before lookup or revocation. Apply database/migrations/20260916_hash_refresh_tokens.sql before deploying this service version; the migration converts existing rows before removing the legacy plaintext column.

πŸ”’ Truxify Security Policy

Truxify is committed to maintaining the highest security standards across our logistics platform, API backend, smart contracts, machine learning pipelines, and mobile applications.


πŸ›‘οΈ Supported Versions

We release regular security patches for active major versions of the Truxify codebase:

Component Supported Version Status
Node.js Express API (backend/api) v1.x βœ… Supported
FastAPI ML Engine (backend/ml) v1.x βœ… Supported
Polygon Smart Contracts (blockchain) Mainnet / Amoy βœ… Supported
Customer & Driver Flutter Apps (apps/) v1.x βœ… Supported

🚨 Reporting a Vulnerability

If you discover a security vulnerability, flaw, or potential exploit in Truxify, please report it responsibly rather than opening a public GitHub issue.

Preferred Reporting Channel:

  • Email: Send your findings to security@truxify.org or contact project leads directly.

What to Include in Your Report:

  1. Description: Clear summary of the potential vulnerability and affected endpoint, contract, or component.
  2. Proof of Concept (PoC): Step-by-step reproduction steps or sample request payloads.
  3. Impact: Assessment of potential operational or data confidentiality risk.

Responsible Disclosure Guidelines:

  • Allow our security team up to 48 hours to acknowledge receipt of your report.
  • We aim to issue a triage assessment within 5 business days and release an appropriate patch within 14 business days.
  • Please do not disclose vulnerabilities publicly until a patch has been officially released.

πŸ”’ Security Architecture Highlights

  • Row Level Security (RLS): Enforced across all PostgreSQL/Supabase database tables.
  • HMAC / JWT Validation: Strict token verification and API Key checks on all inter-service routes.
  • Smart Contract Escrow: Time-locked escrow payments on Polygon blockchain with cryptographic OTP verification.
  • Middleware Protections: Built-in rate limiting, HTTP Parameter Pollution defense, CORS policies, secure cookie flags, and brute-force auth monitoring.

There aren't any published security advisories