# Security at EvoHub

This page describes the measures that protect your EvoHub account and your organization's data, and the settings you control. It only lists what EvoHub actually does today.

## Encryption in transit

All traffic to EvoHub, including the console, the API and the mobile apps, is encrypted in transit with TLS 1.2 or higher.

## Passwords

- Passwords are hashed with bcrypt, a salted one-way hash, before they are stored. EvoHub never stores or logs a password in plain text, and nobody at EvoHub can read yours.
- A password must be at least 8 characters. Administrators can raise the minimum for their organization (see [Login policies](#login-policies)).
- You can sign in with Google or GitHub instead of a password, and connect or disconnect those accounts under **My Account → Authentication → Connected accounts**.

## Sign-in protection

- **Account lock.** After 5 wrong passwords, the account is locked for 15 minutes, even for the right password. This makes guessing passwords slow and expensive.
- **Bot protection.** The sign-in, sign-up, password-reset and verification-email forms are protected by Cloudflare Turnstile, which tells people apart from automated abuse.
- **Two-factor authentication.** Add a time-based one-time code from an authenticator app to every sign-in. See [Two-factor authentication](https://docs-dev.evohub.io/two-factor-authentication.md).
- **Short-lived links.** Password reset links are valid for 15 minutes and email verification links for 24 hours.

## Sessions

- After you sign in, the console holds a short-lived, signed access token that is renewed in the background while you use EvoHub. Sessions are stored on EvoHub's servers and can be ended at any time.
- A session ends after a period of inactivity. The default is 7 days; administrators can change it (see [Login policies](#login-policies)).
- **My Account → Active Sessions** lists every device signed in to your account, with its IP address, when it was last seen and when it signed in. Select **Revoke** to sign a device out. See [Two-factor authentication](https://docs-dev.evohub.io/two-factor-authentication.md#review-your-sessions).
- Signing out ends the session. Deleting your account ends all of them.

## Login policies

Administrators can set security requirements for everyone in an organization under **Organization → Login Policies**:

| Setting | What it does |
| --- | --- |
| **Require MFA** | Every member must set up two-factor authentication before they can enter the organization. |
| **Session Timeout** | Hours of inactivity after which members are signed out. Default 168 (7 days). |
| **Minimum Password Length** | Passwords shorter than this are rejected when members set or change a password. |

Select **Save Policies** to apply them.

## Tenant isolation

Every organization's data is kept apart from every other organization's.

- Every request is tied to exactly one organization by the signed token or API key it carries. EvoHub's servers decide which organization a request belongs to; a client cannot choose it.
- Every read and write of organization data is filtered by that organization. An ID that belongs to another organization simply is not found.
- Inside an organization, work can be scoped to a team. Something that belongs to a team you cannot see is reported as not found, so its existence is not revealed.

## Authorization on the server

- Every action is checked against the caller's organization roles on EvoHub's servers. The console hides what you cannot do, but the API enforces it independently. See [Roles and permissions](https://docs-dev.evohub.io/roles-and-permissions.md).
- You can never grant a role, or give an API key, a permission you do not hold yourself.
- A refused action returns 403. It never signs you out.

## API keys

- An API key is shown once, when it is created. EvoHub stores only a SHA-256 hash of it, so a key cannot be recovered from EvoHub, even by EvoHub.
- A key has exactly the scopes it was given, can expire, and can be revoked instantly. A key never counts as an administrator.
- A personal key loses whatever its owner loses, and stops working when its owner leaves the organization or deletes their account.
- Every key starts with `evohub_`, so secret scanners can recognize a leaked key.

See [API keys and scopes](https://docs-dev.evohub.io/api-keys-and-scopes.md).

## Payment details

Card details are entered into a form provided by Stripe, EvoHub's payment processor. Card numbers go directly to Stripe and never reach EvoHub's servers.

## Audit logs

**Organization → Audit Logs** records administrative and configuration actions, such as creating and revoking API keys and changes to members, roles and settings, across the organization. It is visible to people with an audit-log read permission. The default Admin, Member and Viewer roles all include it; build custom roles without it if you want to restrict who reads the log. Audit logs are kept for 1 year.

## Report a security problem

If you believe your account has been compromised, or you have found a security issue in EvoHub, email info@evosync.io right away.

## Related

- [Two-factor authentication](https://docs-dev.evohub.io/two-factor-authentication.md)
- [Privacy and your data](https://docs-dev.evohub.io/privacy-and-data.md)
- [Roles and permissions](https://docs-dev.evohub.io/roles-and-permissions.md)
- [API keys and scopes](https://docs-dev.evohub.io/api-keys-and-scopes.md)
