Skip to navigationSkip to content

Security controls

Public matrix of Bursa’s technical and organisational security controls.

Public matrix. Internal detail is withheld.

Technical security

  • TLS 1.2+

    Encryption for all client-server traffic

    Live
  • bcrypt passwords

    Password hashes at cost ≥ 12

    Live
  • RBAC

    Role-based access on API and admin

    Live
  • Rate limiting

    Throttles on auth and API endpoints

    Live
  • Input validation

    Zod schemas on API routes

    Live
  • SQLi prevention

    Prisma ORM parameterized queries

    Live
  • XSS prevention

    React auto-escape + DOMPurify

    Live
  • CSRF

    Tokens on sensitive forms

    Partial
  • Audit logging

    Logs for sensitive data access

    Partial
  • KYC field encryption

    KYC/bank columns at rest - not yet

    Planned

Organizational security

  • Incident response

    3-24h breach SOP

    Live
  • Security training

    Engineer onboarding

    Live
  • Change management

    PR review on sensitive code

    Live
  • Vendor assessment

    Sub-processor review

    Partial
  • Access review

    Periodic admin access review

    Planned
  • Admin MFA

    Mandatory admin MFA - Q3 2026

    Planned
  • External pentest

    Planned pre-launch

    Planned

Admin access (public)

  • Learner Notes

    Hard deny - no break-glass

    Live
  • Card data

    Not stored; admin access denied

    Live
  • Passwords / hashes

    Admins cannot read them

    Live
  • User email

    Masked for admin and support

    Partial
  • Mentor KYC

    Compliance only, 24h expiry

    Partial