Security Policy
1. Our Security Commitment
MrInvoice.APP handles your business's billing records, so security is foundational to how we build and operate the Service. This policy describes our security practices and our responsible disclosure program.
2. Site and Service Security Measures
Encryption in transit
All traffic to mrinvoice.app is encrypted via HTTPS/TLS, terminated at Cloudflare's edge and carried to our infrastructure over an encrypted tunnel.
Sign-in protection
- Two-factor by default: every sign-in requires a password plus a fresh one-time code sent by email — every time, for every account
- Private, unlisted sign-in pages delivered by email — never linked from the public site
- Automatic sign-out after 10 minutes of inactivity in the management panels
- Rate limiting on all public forms
No third-party tracking
The Site does not load third-party analytics scripts, advertising pixels, or social media trackers. Only strictly necessary session cookies are set.
Infrastructure
The Site is served through Cloudflare's edge network, which provides built-in DDoS mitigation, WAF protection, and bot management. Our application servers are not directly reachable from the internet.
3. Data Security
- Tenant isolation: every subscriber's records are strictly isolated from every other account at the application layer, verified by automated tests
- Encrypted nightly backups: the full database and documents are backed up off-site every night
- Data minimization: we collect only what is necessary to operate the Service and respond to inquiries
- Access control: access to production systems is limited to authorized personnel
4. Responsible Disclosure
We welcome security researchers who identify vulnerabilities in our website or the Service. We are committed to working with the security community to address issues quickly.
How to report
Use our contact form and mention "Security Disclosure" in your message. Please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact and severity assessment
- Your contact information (optional — we accept anonymous reports)
Our commitments to researchers
- Acknowledge receipt of your report within 48 hours
- Provide an initial assessment within 7 business days
- Remediate critical vulnerabilities within 7 days, and non-critical within 30 days
- Keep you informed of progress (if contact details provided)
- Credit researchers who discover valid vulnerabilities (if desired)
- Not pursue legal action against researchers who act in good faith under these guidelines
What we ask of researchers
- Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
- Do not access, alter, or delete data belonging to other subscribers
- Do not perform denial-of-service, social engineering, or physical attacks
- Allow us reasonable time to remediate before public disclosure
5. Legal Safe Harbor
MrInvoice.APP will not initiate legal action against security researchers who discover and report vulnerabilities in good faith, consistent with these guidelines. We consider good-faith security research to be authorized and will work with researchers rather than against them.
6. Contact
Security disclosures: use our contact form — mention "Security Disclosure".