Security
Last updated: 2026-10-06
An overview of the technical and organizational measures Kwizmo Litoria uses to protect your organization's and employees' data.
Account security
- Passwords are never stored in plain text - only as salted, one-way hashes (PHP's
password_hash(), bcrypt-based).
- Optional two-factor authentication (2FA) via any standard authenticator app (TOTP, RFC 6238), which any organization can require for all its users.
- Session identifiers are regenerated on login to reduce the risk of session fixation.
- Self-service, single-use, time-limited links (via email) for password resets and 2FA recovery - never sent as a shared secret in plain sight.
Application security
- All database queries use parameterized, prepared statements - not string-concatenated SQL - to prevent SQL injection.
- Output is HTML-escaped by default to prevent cross-site scripting (XSS).
- All state-changing form submissions require a CSRF (cross-site request forgery) token.
- Internal application folders (configuration, source code, the database file) are blocked from direct web access.
- Uploaded files (e.g. a custom logo) are validated as genuine images before being accepted, and are always saved under a fixed, predetermined filename - never a name supplied by the uploader - to prevent overwriting arbitrary files.
Data in transit and at rest
All production platform traffic is protected by HTTPS/TLS. Login credentials are never transmitted without encryption.
Access control
Access to an organization's data is restricted to that organization's own users and administrators, and to the platform's super-administrators. Every organization can require 2FA independently, and can have more than one administrator, so access doesn't depend on a single person's availability.
Reporting a security issue
If you believe you've found a security vulnerability, please report it responsibly via our contact form rather than disclosing it publicly, so we can investigate and address it.
This page describes the platform's built-in security measures at a general level. It is not a substitute for your organization's own security assessment of its specific deployment and hosting environment.