Legal
Security Policy
How Outvier protects the website, applications, and user data.
Outvier is operated by Digital Nomad Corporation Pty Ltd and hosted on Amazon Web Services in the Asia Pacific (Sydney) region.
Application security
- HTTPS is required in production, including HTTP to HTTPS redirection at the load balancer
- Secure session and CSRF cookies
- HSTS when served over TLS
- Least-privilege IAM for runtime roles
- Secrets injected at runtime — never committed to Git
Infrastructure security
- Public traffic terminates at an Application Load Balancer
- Application tasks are not intended to be directly reachable from the internet
- Database access is restricted to the application security group
- Container images are scanned on push to Amazon ECR
Reporting
Report suspected vulnerabilities to tech@outvier.com. Please do not publicly disclose issues until we have had a reasonable chance to respond.