ECHOWAVSECHOING EXCELLENCE IN TECH

Security

Security is a boundary, not a marketing badge.

The public website is designed to keep identity credentials and product infrastructure outside the public rendering path.

Identity

Authentication uses EWS Accounts rather than a separate Echowavs password system. Authorization Code + PKCE, state validation and exact registered redirect URIs are used by the integration.

Token handling

OAuth access and refresh tokens are kept in an encrypted HttpOnly server cookie. Browser JavaScript cannot read the session cookie. The server validates the access token against the EWS Accounts userinfo endpoint and attempts provider-issued refresh-token rotation when necessary.

Application security

The site sends security headers including content-type sniffing protection, clickjacking protection, a restrictive permissions policy, referrer policy and a Content Security Policy. Contact submissions are validated server-side, protected by a honeypot and rate-limited per process.

Reporting

A dedicated security reporting address is not published until a monitored production security contact exists. Do not treat the absence of an address as a security guarantee.