TRUST

Security

Hezoya uses industry-standard practices: encrypted transport (HTTPS), password hashing, CSRF protection, session controls, and access-logged admin actions.

Independent assessment

We recommend periodic third-party security review (penetration test / code review) as the product scales. Status of formal certifications (e.g. ISO 27001, SOC 2) will be listed here when obtained.

Responsible disclosure

If you find a vulnerability, email security@hezoya.com with steps to reproduce. Do not access other users’ data or disrupt the service.

← Trust & safety