Account and workspace protection
- Private product areas require a verified sign-in identity.
- Database queries check the signed-in owner before returning or changing workspace records.
- Owner administration is separately restricted to the configured THOBIV administrator.
Forms and uploads
- Public submissions use server-side required-field and field-type validation.
- Rate limits, hidden-field traps and submission-timing checks reduce automated abuse.
- Uploads use a strict file-type and size allowlist, content-signature checks and additional risky-PDF screening.
- Submission files are private and can be opened only by their signed-in form owner.
Network and AI safety
- HTTPS is enforced by the hosting platform and strengthened with transport-security headers.
- Browser security headers restrict content types, permissions and unsafe embedding behaviours.
- AI API keys and administrator configuration stay in backend environment secrets, never in frontend code.
Current launch boundary
Independent email authentication, external malware scanning, off-site backup recovery and payment security require the providers THOBIV will select before full commercial launch. They are not represented as active yet. The current platform provides hosting identity and core infrastructure protection.
Responsible reporting
If you discover a security issue, do not access or change another person’s data. Record the page, time and safe reproduction steps, then report it through the official THOBIV support route when published.