Security

Security by design, not as an afterthought

Projectory treats security and governance as product features: explicit permissions, MFA, audit logging, session safeguards, suspicious activity review, and safer admin controls.

A focused OWASP-oriented review identified weaknesses, fixes were applied, and targeted feature validation passed. The result is a stronger default posture without pushing security work onto customers.

Recent code review and hardening assessment

Critical and high-risk findings were addressed, targeted validation passed, and secure defaults were tightened across admin, API, and deployment surfaces.

Privilege escalation path removed
Admin MFA + re-auth enforced
Deploy runner disabled in production
API auth throttling tightened

Explicit access control

Role-based permissions, project-scoped visibility, and owner-only guardrails keep privilege predictable.

Identity protection

Verified accounts, MFA, trusted devices, and step-up re-authentication protect sensitive admin actions.

Operational visibility

Audit log explorer, high-risk watchlists, suspicious login review, and IP ban tools support investigation and response.

Privacy-conscious defaults

Technical cookies only, no analytics or marketing trackers, and deployment tooling locked down in production.

Identity protection

Admin safeguards with real friction where it matters

Verified accounts, MFA enrollment gates, and recent re-authentication make high-risk admin actions harder to abuse.

Operational visibility

A product team can investigate without guesswork

Audit trails, suspicious login review, and watchlists make the system easier to govern after launch, not just during implementation.

Privacy-conscious defaults

No tracker bloat

Projectory currently uses technical cookies and browser storage for authentication, security, and UI preferences, with no analytics or marketing trackers integrated.