Security

How we protect your data and our commitment to security

Last updated: 9/17/2026

Security Overview

At Phaseview, security is fundamental to everything we do. We understand that environmental professionals trust us with sensitive project data, and we take that responsibility seriously. Our security practices are designed to protect your information at every level.

Data Encryption

In Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3, the latest and most secure transport layer protocol.

At Rest

Sensitive data stored in our databases is encrypted using AES-256 encryption, ensuring protection even in the event of physical access.

Password Security

We never store your password in plain text. Instead, we use Argon2id, the winner of the Password Hashing Competition and recommended by OWASP as the most secure password hashing algorithm available.

  • Memory-hard algorithm resistant to GPU and ASIC attacks
  • Unique salt generated for each password
  • Parameters tuned to OWASP recommendations
  • Regular security reviews of authentication systems

Authentication & Access Control

  • Two-Factor Authentication (2FA): Optional TOTP-based 2FA using authenticator apps like Google Authenticator or Authy for additional account protection.
  • Session Management: Secure, httpOnly cookies with automatic expiration. Sessions are invalidated on password change or suspicious activity.
  • Rate Limiting: Protection against brute-force attacks with intelligent rate limiting on authentication endpoints.
  • Email Verification: All accounts require email verification to prevent abuse and ensure account recovery options.

Infrastructure Security

  • Hosted on enterprise-grade cloud infrastructure with SOC 2 compliance
  • Regular automated backups with encrypted off-site storage
  • Web Application Firewall (WAF) protection against common attacks
  • DDoS protection and traffic filtering
  • Network segmentation and least-privilege access controls
  • Regular security patches and updates

Security Monitoring

We continuously monitor our systems for security threats:

  • 24/7 automated security monitoring and alerting
  • Intrusion detection systems (IDS)
  • Comprehensive logging and audit trails
  • Anomaly detection for suspicious activity
  • Regular penetration testing and security assessments

Responsible Disclosure Policy

We value the security research community and welcome reports of potential security vulnerabilities. If you believe you've found a security issue in our platform, please help us by disclosing it responsibly.

How to Report

Please send security vulnerability reports to: [email protected]

What to Include

  • Description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept code or screenshots
  • Your contact information for follow-up questions

Our Commitment

  • We will acknowledge receipt within 48 hours
  • We will provide an initial assessment within 7 days
  • We will keep you informed of our progress
  • We will not pursue legal action against good-faith researchers
  • We will credit researchers who report valid vulnerabilities (if desired)

Please Do Not

  • Access or modify other users' data
  • Perform denial-of-service attacks
  • Send spam or phishing attempts
  • Publicly disclose vulnerabilities before we've had a chance to address them

Security Best Practices for Users

Help keep your account secure by following these recommendations:

  • Enable Two-Factor Authentication - Add an extra layer of security to your account
  • Use a Strong, Unique Password - Don't reuse passwords from other services
  • Keep Your Email Secure - Your email is used for account recovery
  • Log Out on Shared Devices - Always log out when using public or shared computers
  • Report Suspicious Activity - Contact us immediately if you notice unauthorized access

Security Contact

For security-related inquiries or to report vulnerabilities:

Security Issues: [email protected]

General Support: [email protected]