Account authentication
Account passwords are hashed before storage. The application also implements passkey registration and authentication routes. Session and authorization checks protect signed-in pages and server actions.
This page describes controls visible in the current AdverseMonitor application and states where public assurance evidence is not available. It is not a certification report.
Account passwords are hashed before storage. The application also implements passkey registration and authentication routes. Session and authorization checks protect signed-in pages and server actions.
API requests require bearer authentication. Stored API-key records use a key prefix for identification and a hash for verification. Keys can expire, be revoked, and are subject to plan and endpoint checks.
Application routes and API handlers check the signed-in user before reading or changing customer data. Queries include the authenticated user ID when they access profiles, keys, usage, and support records.
Authentication, general application requests, and public API use have implemented rate-limit checks. API usage and application activity are recorded for operational review.
Customer alert delivery to Email, Slack, Teams, browser push and webhooks is disabled. The application records new profile matches in the signed-in dashboard.
The product matches customer-supplied terms against collected threat records. It does not require an agent inside the customer network for the monitoring workflow described on this site.
If you believe you found a vulnerability, send a concise report to security@adversemonitor.com with the affected URL, reproduction steps, potential impact, and any supporting evidence. Do not access other users’ data, disrupt service, or use social engineering.
This address is for inbound reports. Visiting this page or using the product does not trigger an email.