Identity
Authentication uses EWS Accounts rather than a separate Echowavs password system. Authorization Code + PKCE, state validation and exact registered redirect URIs are used by the integration.
Token handling
OAuth access and refresh tokens are kept in an encrypted HttpOnly server cookie. Browser JavaScript cannot read the session cookie. The server validates the access token against the EWS Accounts userinfo endpoint and attempts provider-issued refresh-token rotation when necessary.
Application security
The site sends security headers including content-type sniffing protection, clickjacking protection, a restrictive permissions policy, referrer policy and a Content Security Policy. Contact submissions are validated server-side, protected by a honeypot and rate-limited per process.
Reporting
A dedicated security reporting address is not published until a monitored production security contact exists. Do not treat the absence of an address as a security guarantee.