Platform security
How Webforta protects your data and the outbound scanner.
- Passwords hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, the Workers maximum) and unique salts.
- Sessions use random 256-bit tokens stored only as SHA-256 hashes, in __Host- cookies with HttpOnly, Secure and SameSite=Lax; idle timeout 3 days, absolute 14 days.
- CSRF protection with origin validation and per-session tokens; strict Content Security Policy without inline scripts.
- Every query on customer data is scoped to the organization from the server-side session or API key.
- Rate limits on sign-in, registration, password reset, verification, scans, contact and API usage.
- Third-party API tokens encrypted with AES-256-GCM using a key held as a Cloudflare secret.
- Audit log of sensitive actions; IP addresses are stored only as keyed hashes.
- Scanner SSRF defences: HTTP/HTTPS only, default ports only, no IP literals, DNS answers validated against private and reserved ranges before every connection and redirect, response size and time limits.
Known limitation
Cloudflare Workers resolve DNS themselves when connecting, so Webforta cannot pin a connection to the exact address it validated. A malicious DNS server could change its answer between validation and connection (DNS rebinding). Webforta re-resolves short-TTL hostnames after each request and discards responses when the answer changes to a private address, only contacts verified hostnames, and runs on Cloudflare’s network where no private customer network or cloud metadata service is reachable.