Security controls
Public matrix of Bursa’s technical and organisational security controls.
Public matrix. Internal detail is withheld.
Technical security
- Live
TLS 1.2+
Encryption for all client-server traffic
- Live
bcrypt passwords
Password hashes at cost ≥ 12
- Live
RBAC
Role-based access on API and admin
- Live
Rate limiting
Throttles on auth and API endpoints
- Live
Input validation
Zod schemas on API routes
- Live
SQLi prevention
Prisma ORM parameterized queries
- Live
XSS prevention
React auto-escape + DOMPurify
- Partial
CSRF
Tokens on sensitive forms
- Partial
Audit logging
Logs for sensitive data access
- Planned
KYC field encryption
KYC/bank columns at rest - not yet
Organizational security
- Live
Incident response
3-24h breach SOP
- Live
Security training
Engineer onboarding
- Live
Change management
PR review on sensitive code
- Partial
Vendor assessment
Sub-processor review
- Planned
Access review
Periodic admin access review
- Planned
Admin MFA
Mandatory admin MFA - Q3 2026
- Planned
External pentest
Planned pre-launch
Admin access (public)
- Live
Learner Notes
Hard deny - no break-glass
- Live
Card data
Not stored; admin access denied
- Live
Passwords / hashes
Admins cannot read them
- Partial
User email
Masked for admin and support
- Partial
Mentor KYC
Compliance only, 24h expiry