Security

How we protect your data.

This page is maintained by Desert Oasis Digital LLC to answer common security and privacy questions about AwardReady. Nothing here is a substitute for independent certification.

Encryption in transit and at rest

TLS 1.3 for every request. AES-256 encryption at rest for every database row and document.

Row-level security

Strict per-user and per-entity isolation enforced at the database. No cross-tenant leakage — even from a hypothetical application bug.

Two-factor authentication

TOTP-based 2FA available on every account. Backup codes issued at enrollment, regeneratable at any time.

60-minute idle session timeout

Sessions expire automatically after 60 minutes of inactivity. Sign-out is enforced client-side and server-side.

Signed document URLs

Every uploaded document is served through a URL that expires after one hour. No public links, ever.

Audit logging

IP address and user identity are logged on every login, every data mutation, and every team-membership change. Users can view their own audit trail.

Network protection

Cloudflare-managed WAF and DDoS protection at the edge. Access from mainland China blocked at the network layer.

No advertising trackers

Zero third-party ad or analytics trackers. Only functional cookies necessary for authentication.

Responsible disclosure

If you believe you've discovered a security vulnerability in AwardReady, we'd like to hear about it. Please report through our Contact page with the subject line "Security" and include a description of the issue, reproduction steps, and any relevant impact assessment. We'll acknowledge within one business day and work with you in good faith to resolve the issue before disclosure.