Security Overview
Last updated: August 24, 2026
1. Purpose
This document provides a high-level overview of the security measures implemented by Universal Life Source (ULS) to protect user data and platform integrity. It is intended for technical evaluators assessing the platform for organizational use.
For specific implementation details or a formal security assessment, contact us at [email protected].
2. Infrastructure Overview
| Layer | Provider | Role |
|---|---|---|
| Edge Protection | Cloudflare | TLS termination, DDoS protection, WAF, DNS management |
| Application Hosting | Railway (US East) | Containerized Python application |
| Database | Railway PostgreSQL | Primary data store with point-in-time recovery backups |
| Authentication | Logto | OIDC identity provider, MFA, enterprise SSO |
| AI Processing | OpenAI / NVIDIA | Answer generation and semantic search embeddings |
3. Encryption
- In transit: All network traffic is encrypted with TLS 1.3 via Cloudflare. Database connections require SSL/TLS.
- API keys at rest: User-provided API keys (BYOK) are encrypted using symmetric encryption before database storage. The encryption key is stored in a secure environment variable, never in the database or source code.
- Session tokens: JWT-based session tokens are signed with a secret key stored in a secure environment variable.
4. Authentication
- Identity provider: Authentication is managed by Logto, a dedicated OIDC provider. Passwords are never stored in the ULS database.
- Multi-factor authentication: MFA is supported via authenticator apps (TOTP) and can be enforced for organization members.
- Enterprise SSO: SAML-based single sign-on is supported for organizations that require it.
- Session management: Sessions use HttpOnly, Secure, SameSite cookies with an 8-hour expiry.
- CSRF protection: All form submissions require a CSRF token.
5. Access Control
- Route-level: All application routes require authentication unless explicitly public (legal pages, login).
- Organization-level: Multi-tenant architecture with role-based access control (owner, admin, member, viewer).
- Data isolation: User data is scoped to the user's organization. Cross-tenant access is prevented at the query level.
6. Application Security
- SQL injection prevention: All database queries use parameterized execution.
- XSS prevention: Content Security Policy headers, HTML auto-escaping in templates.
- Rate limiting: Per-endpoint rate limits on authentication, search, and AI endpoints to prevent abuse.
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
- Origin protection: The application is only accessible through the Cloudflare-proxied domain. Direct access to backend infrastructure is blocked.
- Secret management: All secrets (database credentials, API keys, session signing keys) are stored in environment variables, never in source code or version control.
7. Audit Logging
ULS maintains an audit log of security-relevant actions, including:
- Authentication events (login success, login failure, logout)
- Data modifications (journal entries, research sessions, collections)
- Administrative actions (user management, organization changes, BYOK configuration)
Audit logs are retained for 90 days and automatically purged thereafter.
8. Data Backups
- Point-in-time recovery: The primary database has continuous WAL archiving enabled, allowing restoration to any recent point in time.
- Volume backups: Scheduled volume snapshots provide an additional recovery layer.
9. Independent Verification
The ULS source code has undergone independent security review covering SQL parameterization, secret management, encryption practices, and AI data handling. Verified findings are available upon request for qualified evaluators.
Contact [email protected] to request verification documentation.
10. Reporting Security Issues
If you believe you have identified a security vulnerability in ULS, please report it responsibly to [email protected]. We ask that you do not publicly disclose the issue until we have had an opportunity to investigate and respond.
Please include:
- A description of the vulnerability
- Steps to reproduce (if applicable)
- Your assessment of the potential impact
We will acknowledge receipt within 48 hours and provide a substantive response within 5 business days.
11. Contact
For security questions, assessments, or enterprise evaluation support, contact [email protected].