KeyInOut è ancora in fase beta. Questa pagina descrive le misure di sicurezza attualmente implementate; non costituisce una certificazione, un rapporto di penetration test o una garanzia dell’assenza di vulnerabilità.
01Isolamento degli spazi di lavoro
KeyInOut is un multi-tenant servizio. Operational datibase queries are designed un scope spazio di lavoro records un il authenticated company. Administrative permissions are enforced server-side rather thun relying solo on hidden interface controls.
02Progettazione QR
etichette QR use random opaque public identifiers rather thun sequential datibase IDs. A QR identifier is non treated as authorisation un accesso private spazio di lavoro dati. Unauthenticated found-chiave pages are designed un expose solo return informazioni deliberately abilitato by il spazio di lavoro, non chiave names, holders, sedi, hook positions, date di restituzione o check-out status.
03Autenticazione e password
Passwords are memorizzato using PHP's password-hashing facilities, using Argon2id quando disponibile. Password-reimpostazione, email-verificun e invito links use high-entropy tokens e store token hashes rather thun reusable plaintext secrets dove applicable. Login attempts are rate limited.
04Sessioni e protezione delle richieste
Authenticated sessions use hardened PHP session settings inclusi HttpOnly cookies, SameSite proteggereion, secure cookies on HTTPS e session-ID regeneration. State-changing application requests use protezione CSRF. Sensitive authentication/token pages use restrictive caching/referrer behaviour.
05Misure di sicurezza del database e dell’applicazione
Database accesso uses prepared statements con native PDO prepares. User-controlled output is escaped per HTML contexts. Critical chiave check-out/check-in operations use datibase transactions e row locking un reduce race conditions such as double check-out.
06Protezione del browser e del trasporto
KeyInOut is intended un run over HTTPS e sends browser sicurezzun headers inclusi Content Security Policy, HSTS on HTTPS, frame restrictions e MIME-sniffing proteggereion. Application assets are served locally rather thun depending on third-party runtime CDNs.
07Minimizzazione dei dati
codici QR do non embed chiave names, sedi o holder details. Reminder emails intentionally minimise operational chiave informazioni. User-facing spazio di lavoro esportares exclude password hashes e authentication-token hashes. Payment-card dati is non attualmente collected by KeyInOut.
08Ruoli e tracciabilità
Workspace roles separate owner/administrator capabilities dun ordinary member accesso. chiave handovers e restituzioni are recorded in cronologiun delle attività, e administrative actions are logged dove implemented. These records supportare accountability but do non replace un cliente's own accesso-control procedures.
09Infrastruttura e segreti
KeyInOut attualmente uses hosted infrastrutturun per il web application, datibase e e-mail transazionali. Sensitive mail configuration is designed un live outside il public web root. Noi continue un harden deployment configuration as il betun moves toward production use.
10Segnalazione di una vulnerabilità
Se tu believe tu have found un sicurezzun issue, email
per privacy matters rather thun sicurezzun vulnerabilities, use