CeibaInkBack / Volver
Security · Seguridad

Security

How CeibaInk protects accounts and platform operations.

Security controls / Controles de seguridad

  • HTTPS is required for production traffic.
  • Google Sign-In tokens are verified by the CeibaInk backend before a session is opened.
  • Role and business permissions are enforced server-side, not only by hiding interface controls.
  • Database inputs use parameterized/prepared operations where applicable.
  • Uploads are validated by the server before being accepted.
  • Session, CSRF, rate-limit and audit controls are used for sensitive operations.
  • Release Android credentials and upload keys are not embedded in public source or transmitted to CeibaInk users.

To report a suspected vulnerability, contact support@ceibag.online with enough detail to reproduce the issue. Please do not access other users' data or disrupt the service while testing.

Español

CeibaInk exige HTTPS en producción, valida los tokens de Google en el servidor, aplica permisos de roles del lado del backend, valida archivos subidos y utiliza controles de sesión, CSRF, limitación de intentos y auditoría en operaciones sensibles. Para reportar una vulnerabilidad escribe a support@ceibag.online.

© 2026 CeibaInk
PrivacyTermsSecuritySupport