Passwords are one-way hashed using a memory-hard password hashing algorithm.
Controls that belong to the application.
Abnio treats edge services as optional layers, not the foundation. Authentication, authorization, tenant isolation and collection correctness are enforced by Abnio itself.
Security overview · Updated 25 August 2026
Account and access protection
Every customer account is protected by app-native two-factor authentication, and access is resolved against the requested site on every analytics route.
Authenticator-app codes are enforced before customer site data loads, with single-use recovery codes.
Browser sessions remain server-controlled, and state-changing requests use CSRF protection.
Analytics routes resolve site grants explicitly; admin and viewer permissions remain distinct.
Internal access can be limited by both role and an explicit site allow-list.
Administrative mutations create audit records for later review and incident investigation.
Collection and data safeguards
Security also means reducing what can be exposed. Abnio avoids raw IP storage and durable cross-site browser identity, and protects the credentials that integrations depend on.
Public application and collection surfaces are served over HTTPS.
IP addresses are transformed transiently into scoped hashes and are not stored as raw values.
Google OAuth refresh tokens and TOTP secrets are encrypted at rest.
Overlapping active tokens allow planned rotation without data loss; the last active token cannot be revoked.
Install verification restricts destinations, revalidates redirects and addresses, and caps time and body size.
Public collection returns minimal bodyless responses and avoids leaking tenant detail through errors.
Found something? Tell us privately.
Report a suspected vulnerability with enough detail for us to reproduce it, and give us room to investigate before it goes public.
Report it through contactName the affected surface, give reproduction steps and describe the potential impact.
Do not access another customer’s data or degrade the service while you investigate.
Do not use social engineering against people or accounts to demonstrate a finding.
Hold public details until we have had a reasonable opportunity to investigate.
Bring the security questions early.
Access, data handling and regional requirements are reviewed during onboarding, alongside the privacy model that decides what gets collected in the first place.