Security
How Evacor protects your account and your workspace's data. This page describes how the product works today and is not an audit report or a certification.
One account, no passwords between apps
You sign in once, on accounts.evacor.io. Opening an app from your account uses a single-use token that is stored hashed and expires after 3 minutes. The apps never see your password.
Passwords
Passwords are stored hashed with scrypt, never in plain text.
Workspace separation
Data access is scoped to the workspace you are signed in to, and automated tests try to read one workspace's data from another.
Roles
Every member of a workspace is an Owner, an Admin or a Member. Only the Owner can change the plan and billing, delete the workspace or hand it to someone else. Owners and Admins manage settings and members.
Audit log
Changes to workspace settings, members and roles are recorded with who made them and when, and workspace entries cannot be edited or deleted afterwards.
Protection against guessing
Sign in, sign up, password reset and the hand-off into each app have a rate limit, so repeated attempts are slowed down and refused.
Report a security problem
If you find a problem, write to product@bsq.agency with the subject “Security report”. Give us a reasonable time to fix it before you disclose it. If you act in good faith, avoid harm to other people's data and do not access more than you need to show the issue, we will not take legal action against you. Our contact details for researchers are also in /.well-known/security.txt.