Security

How we protect your data and keep MyAlwaysOn secure.

◆

Our Commitment

Security is foundational. We encrypt everything in transit, hash passwords with bcrypt, and continuously review our systems for weaknesses.

Technical Measures

◈ HTTPS Everywhere
All traffic is encrypted with TLS 1.2+. HTTP requests are automatically redirected to HTTPS.
◈ Password Security
Passwords are hashed with bcrypt using PHP's recommended cost factor. We never store plaintext passwords.
◈ CSRF Protection
All POST requests require a valid CSRF token tied to your session.
◈ SQL Injection Prevention
Any query involving user input uses prepared statements. User-supplied values are never concatenated into SQL strings.
◈ XSS Protection
All user-generated content is escaped before rendering.
◈ Session Security
Session cookies are HttpOnly, Secure, and SameSite=Lax. Sessions regenerate on login.
◈ Sensitive Paths Blocked
Config files, environment variables, and source code are outside the web root.

What We're Still Building

We'd rather tell you what we don't have yet than pretend we're bigger than we are:

  • Two-factor authentication is not yet available. It is on our roadmap.
  • Independent third-party security audit — we run automated scans and manual review, but have not yet commissioned an external audit. When we do, we'll say so here.

If a Breach Happens

If a security incident affects your account, we will notify you by email within 72 hours of discovery, describing what happened, what data was involved, and what you should do.

Report a Vulnerability

If you discover a security issue, please email us directly. We respond within 24 hours.

📧 Report to hello@myalwayson.com

Please do not publicly disclose vulnerabilities before we've had a chance to fix them.

📡 Send a Signal

0 / 500

🎁 Send a Gift

To: @user

Balance: ⧫ 0