অ্যাকাউন্ট নিরাপত্তা
- পাসওয়ার্ড industry-standard work-factor algorithm-এ hash করা হয় — আমরা কখনো plain টেক্সট-এ স্টোর করি না।
- Sensitive action (পেআউট detail পরিবর্তন, data export) করতে রেজিস্টার্ড ইমেইল-এ পাঠানো one-time code লাগে।
- Inactivity-র পর session auto-expire হয়, এবং remote session-গুলো অ্যাকাউন্ট পেজ থেকে sign-out করা যায়।
পেমেন্ট নিরাপত্তা
- কার্ড পেমেন্ট PCI-DSS-compliant গেটওয়ে (SSLCommerz)-এ process হয়। SGT কার্ট কখনো raw কার্ড number স্টোর করে না।
- সমস্ত পেমেন্ট-পেজ traffic end-to-end TLS-encrypted।
- সন্দেহজনক পেমেন্ট pattern ফান্ড রিলিজ-এর আগে automated রিভিউ trigger করে।
Platform নিরাপত্তা
- Production server reverse proxy-র পেছনে HSTS, modern TLS ও rate-limited public endpoint দিয়ে isolated।
- Internal access least-privilege, MFA-enforced, এবং logged।
- Backup encrypted at rest এবং restorability নিয়মিত test করা হয়।
Vulnerability রিপোর্ট
Security researcher-রা, proof-of-concept ও আপনার যোগাযোগ detail-সহ security@sgtcart.com-এ ইমেইল করুন। আমাদের commitment:
- ২ কর্মদিবস-র মধ্যে acknowledgement।
- Other user-দের impact না করা good-faith research-এর জন্য safe-harbour।
- Fix শিপ হওয়ার পর আপনার পছন্দ অনুযায়ী public credit।