AWS-Grade Hardening
VenXoX is built on a distributed, global architecture hosted on Amazon Web Services (AWS) and Vercel. We leverage the world's most advanced infrastructure to ensure 99.9% uptime and rapid responses to security threats.
Our network is protected by professional-grade Web Application Firewalls (WAF) and DDoS protection services that automatically filter out malicious traffic before it ever hits our servers.
Encryption at Every Layer
We treat your data with the highest level of care.
- In Transit: All data moving between your device and our servers is encrypted using Transport Layer Security (TLS 1.3).
- At Rest: Sensitive data, including DMs and personal identifiers, is encrypted using Advanced Encryption Standard (AES-256) before it hits our storage buckets.
- Hashed Passwords: We never store your password in plain text. We use Argon2 hashing algorithms to ensure that even in the event of a breach, your credentials remain secure.
Your Personal Shield
We provide several tools to help you protect your own account:
- Two-Factor Authentication (2FA): Secure your account with a secondary code sent via SMS or an auth app.
- Login Alerts: Get notified immediately via email if your account is accessed from a new device or location.
- Biometric Unlock: Use FaceID or Fingerprint scan to open the app on supported devices.
- Session Management: View and remotely log out of all active devices from your settings.
Collaborating with White-Hats
We believe in the power of the security community. VenXoX maintains a private bug bounty program for vetted security researchers.
If you are a security researcher and have discovered a vulnerability in our platform, please reach out to security@venxox.comto be considered for our program. We offer competitive rewards for confirmed high-impact vulnerabilities.
How to Report a Vulnerability
If you are not part of our bounty program but have found a vulnerability, we ask that you follow these guidelines:
- Notify us immediately: Email disclosure@venxox.com with details.
- Give us time: Allow a reasonable period (typically 30-90 days) for us to address the issue before making it public.
- Do no harm: Do not attempt to access, modify, or delete user data during your investigation.
Our Commitment to Truth
VenXoX publishes bi-annual Transparency Reports. These reports summarize:
- Government requests for user data.
- Account takedown requests for Guideline violations.
- Summary of security incidents and our response times.
We believe that transparency builds trust, and trust is the foundation of any authentic connection.