Security
The security of the data you give us access to is fundamental to the dashiox service. This page summarises the main measures and the rules for reporting vulnerabilities.
Encryption
- All communication with the service takes place exclusively over HTTPS (TLS) with HSTS enabled; the same applies to the service's communication with platform APIs.
- Platform access and refresh tokens (Google) are stored encrypted with AES-256-GCM; the key is kept separately from the database.
- Passwords are stored only as a hash (Argon2id); session and invitation identifiers only as a hash (SHA-256).
Data isolation
- The data of each workspace is logically separated; permissions are checked on every request both in the application and in the database (row-level security).
- The portal, the administration and the interface for AI clients (MCP) run on separate hosts with separate sessions and cookies.
- Analyses and findings are delivered only to you and to the AI client you connected and authorised yourself; you can remove its access at any time by removing the connector in the AI client, or by asking us by e-mail (in the portal once available).
Sign-in and permissions
- Accounts are created by invitation only; sign-in requires a password and two-factor authentication (TOTP), or sign-in with a verified Google account with the same e-mail (sign-in security is then governed by the Google account; signing in with Google never creates an account without an invitation).
- Sign-in attempts are rate-limited, forms are protected against CSRF and pages by strict security headers (a Content Security Policy with no external sources).
- The service makes no changes in platform accounts during the beta; change proposals (coming soon) will be carried out only after your explicit approval.
- The operator's administrative access is separate, protected by two-factor authentication and audited; we access user data only as described in the Privacy Policy.
Backups
We back up the database and configuration regularly. Backups are stored with restricted access and rotated regularly, and deleted data disappears from them no later than 30 days after deletion from the production system.
Operations
- The servers run at the provider listed on the subprocessors page with restricted network access, automatic security updates and protection against repeated sign-in attempts.
- Tokens, passwords and keys are automatically masked in logs; logs do not contain the content of platform data.
Reporting vulnerabilities
If you find a security issue, please write to (machine-readable details are in security.txt). We communicate in Czech and English.
- Describe the issue and the steps to reproduce it; share sensitive data only to the extent necessary.
- Test only with your own account, do not access, modify or delete other users' data, do not disrupt the service (no DoS attacks, spam or social engineering) and do not test the infrastructure of the platform providers.
- Give us reasonable time to fix the issue before disclosing it; we will acknowledge your report and keep you informed about the fix.
- We will not take legal action against researchers who act in good faith and follow these rules. We do not currently offer financial rewards (bug bounty).
Version 1.3, effective from 28 September 2026