BlockACountry

Security

Security controls you can inspect

Factual controls for authentication, account access, provider authorization, and reproducible deployment.

Secure authentication

Password hashing, email verification, password confirmation, rate limits, two-factor authentication, recovery codes, and supported passkeys protect account access.

Account and role controls

Accepted account memberships and scoped roles separate owners, managers, members, and platform administration.

OAuth and encrypted credentials

Cloudflare and Google authorization use state and PKCE. Stored access and refresh tokens use encrypted model casts and are not rendered back to customers.

Reproducible configurations

Generated artifacts retain policy revision, renderer version, checksum, and frozen dataset provenance.

Data minimisation

Hosted block telemetry excludes request bodies, query strings, cookies, authorization headers, full referrers, raw User-Agent strings, and persistent raw IP storage.

Protection continuity

Generated origin rules and deployed provider rules do not depend on dashboard availability or optional telemetry to continue enforcing.

Report a security issue

Use the configured security contact on the Contact page. If it is not configured, production launch remains blocked on that operational requirement.