1. Security Controls
- Authenticated app routes and protected server APIs.
- Input validation and server-side product allowlisting for checkout.
- Rate limiting on sensitive endpoints (checkout, portal, and plan checks).
- Security headers on application responses.
2. Monitoring and Incident Response
We monitor production systems and investigate security events. When incidents are confirmed, we contain impact and deploy mitigation as quickly as possible.
3. Responsible Disclosure
Report security concerns to support@blokrly.com with steps to reproduce and impact details.