Security at Webforta
How we protect your account, your data and the websites you monitor.
- Passwords hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, the Workers maximum) and unique salts.
- Sessions use random 256-bit tokens stored only as SHA-256 hashes, in __Host- cookies with HttpOnly, Secure and SameSite=Lax; idle timeout 3 days, absolute 14 days.
- CSRF protection with origin validation and per-session tokens; strict Content Security Policy without inline scripts.
- Every query on customer data is scoped to the organization from the server-side session or API key.
- Rate limits on sign-in, registration, password reset, verification, scans, contact and API usage.
- Third-party API tokens encrypted with AES-256-GCM using a key held as a Cloudflare secret.
- Audit log of sensitive actions; IP addresses are stored only as keyed hashes.
- Scanner SSRF defences: HTTP/HTTPS only, default ports only, no IP literals, DNS answers validated against private and reserved ranges before every connection and redirect, response size and time limits.
Known limitation
Cloudflare Workers resolve DNS themselves when connecting, so Webforta cannot pin a connection to the exact address it validated. A malicious DNS server could change its answer between validation and connection (DNS rebinding). Webforta re-resolves short-TTL hostnames after each request and discards responses when the answer changes to a private address, only contacts verified hostnames, and runs on Cloudflare’s network where no private customer network or cloud metadata service is reachable.
Infrastructure
Webforta runs on Cloudflare Workers with data stored in Cloudflare D1. Secrets are held as encrypted Cloudflare environment secrets, never in source code.
Certifications
Webforta does not currently hold third-party security certifications such as SOC 2 or ISO 27001.
Report a vulnerability
See our Responsible Disclosure Policy or security.txt.