Skip to content

Security Policy

How we protect your data, what our scanner does and does not touch, and how to report a vulnerability to us.

Last updated: 6 August 2026 · Policy version: 2026-08-06-v1

Encryption in transit

All communication between your device and Nivaronix is encrypted using TLS 1.2 or higher. That covers:

  • Login credentials
  • Sensitive data transfer
  • API communication
  • Scan results and reports

Authentication and access control

  • Secure password requirements and validation
  • Session-based authentication with secure tokens
  • Rate limiting on failed login attempts, by IP address and by email address. Note this is throttling, not lockout — repeated attempts are slowed and refused, and an account is never locked out of its own access.
  • Session expiry for inactive accounts
  • Role-based access control for platform features

Storage and monitoring

User data is stored in a managed database with restricted access. Backups run nightly, so a failure could lose up to 24 hours of data. There is no automatic failover and no second region — our reliability page states the architecture in full. Application activity is recorded in security event logs; we do not run network-level intrusion detection.

Our reliability page sets out the architecture in full, including where it is single-homed and what that means for you.

Scanning and your data

When you submit a domain for scanning, Nivaronix:

  • Only analyzes publicly available information (SSL/TLS, DNS, headers)
  • Does not crawl or access website content
  • Does not store copies of website data
  • Retains scan results only for your account

Our Privacy Policy lists every provider that receives data, exactly what we send them, and how long scan and security logs are kept.

Standards we work to

Nivaronix follows industry security best practices and standards, including:

  • OWASP Top 10 mitigation
  • Secure coding practices
  • Dependency and container vulnerability scanning on every build
  • Least privilege access

If there is an incident

In a security incident we act immediately to investigate, contain and remediate it. Where an incident affects your data, we notify you in accordance with applicable law.

Your part

You are responsible for keeping your account credentials confidential:

  • Use a strong, unique password
  • Never share your login credentials
  • Log out when finished, especially on a shared device
  • Report suspicious account activity immediately

Reporting a vulnerability

We appreciate researchers who report vulnerabilities responsibly. Email [email protected] with the details, and we will investigate and work with you to resolve the issue. The same address is the right one for any other security concern or question.

Nivaronix is operated by Pravin Gyawali, based in Butwal, Nepal. Reports are handled by the operator directly rather than by a staffed security team, so please allow a reasonable time for an initial acknowledgement.

Our other policies