Security
Protecting your data and assets is our top priority. Here's how we keep your information safe.
Encryption
Connections are served over HTTPS. TLS is terminated by the hosting provider; this application does not choose cipher suites itself. Authentication tokens are stored in httpOnly cookies that are marked secure in production.
Application field encryption (AES-256-GCM) covers employee street address lines, postal code, and free-text notes. Phone number, city, and province are not field-encrypted. Everything else relies on disk encryption provided by the database host (Neon) and the application host (Vercel). BoomerangDepot does not implement disk encryption, and field encryption does not cover every column.
Authentication
JWT-based authentication with automatic token rotation, session management, and bcrypt password hashing with a cost factor of 12. Platform admins, company admins, and support staff use an authenticator app (TOTP). Impersonation, personal-data export, and destructive deletes by those roles require a fresh code.
Access Control
Role-based access control ensures users only see data relevant to their organization. Admin actions are logged and auditable.
Infrastructure
Hosted on enterprise-grade cloud infrastructure with rate limiting, DDoS protection, and comprehensive security headers including CSP.
Report a Vulnerability
Found a security issue? Please report it responsibly to info@boomerangdepot.ca.