Refresh tokens are bearer credentials and must never be stored in plaintext. The API stores SHA-256 digests in refresh_tokens.token_hash and hashes incoming tokens before lookup or revocation. Apply database/migrations/20260916_hash_refresh_tokens.sql before deploying this service version; the migration converts existing rows before removing the legacy plaintext column.
Truxify is committed to maintaining the highest security standards across our logistics platform, API backend, smart contracts, machine learning pipelines, and mobile applications.
We release regular security patches for active major versions of the Truxify codebase:
| Component | Supported Version | Status |
|---|---|---|
Node.js Express API (backend/api) |
v1.x |
β Supported |
FastAPI ML Engine (backend/ml) |
v1.x |
β Supported |
Polygon Smart Contracts (blockchain) |
Mainnet / Amoy | β Supported |
Customer & Driver Flutter Apps (apps/) |
v1.x |
β Supported |
If you discover a security vulnerability, flaw, or potential exploit in Truxify, please report it responsibly rather than opening a public GitHub issue.
- Email: Send your findings to
security@truxify.orgor contact project leads directly.
- Description: Clear summary of the potential vulnerability and affected endpoint, contract, or component.
- Proof of Concept (PoC): Step-by-step reproduction steps or sample request payloads.
- Impact: Assessment of potential operational or data confidentiality risk.
- Allow our security team up to 48 hours to acknowledge receipt of your report.
- We aim to issue a triage assessment within 5 business days and release an appropriate patch within 14 business days.
- Please do not disclose vulnerabilities publicly until a patch has been officially released.
- Row Level Security (RLS): Enforced across all PostgreSQL/Supabase database tables.
- HMAC / JWT Validation: Strict token verification and API Key checks on all inter-service routes.
- Smart Contract Escrow: Time-locked escrow payments on Polygon blockchain with cryptographic OTP verification.
- Middleware Protections: Built-in rate limiting, HTTP Parameter Pollution defense, CORS policies, secure cookie flags, and brute-force auth monitoring.