Controls that belong to the application.

Abnio treats edge services as optional layers, not the foundation. Authentication, authorization, tenant isolation and collection correctness are enforced by Abnio itself.

Security overview · Updated 25 August 2026

Account and access protection

Every customer account is protected by app-native two-factor authentication, and access is resolved against the requested site on every analytics route.

Argon2id passwords

Passwords are one-way hashed using a memory-hard password hashing algorithm.

Required TOTP 2FA

Authenticator-app codes are enforced before customer site data loads, with single-use recovery codes.

Server-side sessions

Browser sessions remain server-controlled, and state-changing requests use CSRF protection.

Tenant boundaries

Analytics routes resolve site grants explicitly; admin and viewer permissions remain distinct.

Scoped operations

Internal access can be limited by both role and an explicit site allow-list.

Auditability

Administrative mutations create audit records for later review and incident investigation.

Collection and data safeguards

Security also means reducing what can be exposed. Abnio avoids raw IP storage and durable cross-site browser identity, and protects the credentials that integrations depend on.

TLS in transit

Public application and collection surfaces are served over HTTPS.

No raw IP database

IP addresses are transformed transiently into scoped hashes and are not stored as raw values.

Encrypted integration tokens

Google OAuth refresh tokens and TOTP secrets are encrypted at rest.

Safe ingest rotation

Overlapping active tokens allow planned rotation without data loss; the last active token cannot be revoked.

Hardened verification

Install verification restricts destinations, revalidates redirects and addresses, and caps time and body size.

Quiet collection contract

Public collection returns minimal bodyless responses and avoids leaking tenant detail through errors.

Found something? Tell us privately.

Report a suspected vulnerability with enough detail for us to reproduce it, and give us room to investigate before it goes public.

Report it through contact
What to send Surface, steps, impact

Name the affected surface, give reproduction steps and describe the potential impact.

Stay in bounds No other customer’s data

Do not access another customer’s data or degrade the service while you investigate.

Stay in bounds No social engineering

Do not use social engineering against people or accounts to demonstrate a finding.

Before publishing Give us time to look

Hold public details until we have had a reasonable opportunity to investigate.

Bring the security questions early.

Access, data handling and regional requirements are reviewed during onboarding, alongside the privacy model that decides what gets collected in the first place.