BBelobrov Technologies
Request pilot
Trust / Security

Security & Assurance

What Belobrov Technologies protects today, what it does not claim, and how security issues should be reported.

1. Current controls

  • Server-only access to privileged Supabase credentials.
  • Row-level security plus explicit browser-role privilege restrictions on administrative data tables.
  • Service-role-only execution for privileged database functions.
  • HttpOnly, SameSite=Strict administrator sessions with expiration and secure production cookie settings.
  • Production login rate limiting using pseudonymous source fingerprints.
  • Administrative audit logging for important operational actions.
  • HMAC-based pseudonymous fingerprints for verification deduplication and anomaly signals.
  • No intentional storage of raw IP addresses or full user-agent strings in new product-scan records.
  • Explicit browser prefetch traffic is excluded from verification telemetry. Client-declared User-Agent strings are not trusted as a security control.
  • Content Security Policy, HSTS, clickjacking protection, MIME-sniffing protection, referrer controls and restrictive browser permissions.
  • Product and logo images are uploaded to controlled storage, decoded, size-limited and re-encoded to WebP rather than hot-linked from arbitrary third-party hosts.
  • Administrative and product-verification routes are marked noindex and served with no-store cache controls.

Updated: 10 September 2026.

2. Product-authentication assurance

Belobrov Technologies separates registry verification from cryptographic authenticity. Static URLs, QR codes and many low-cost NFC UIDs can be copied or emulated. Current pilot deployments can detect suspicious reuse patterns, but should not be described as “unclonable” unless cryptographic tag verification is actually implemented for that deployment.

3. Risk intelligence

Risk scores are generated from behavioral signals such as rapid repeated verification, distinct pseudonymous request fingerprints and approximate location changes. Network routing, VPN use and IP geolocation can produce false positives, so risk signals should be reviewed rather than treated as proof of counterfeiting or fraud.

4. Image handling

Uploaded JPEG, PNG and WebP images are limited in size, decoded by the service and converted to WebP before publication. This reduces metadata leakage and prevents public product pages from silently loading arbitrary customer-supplied third-party image hosts.

5. Vulnerability reporting

If you believe you have found a security issue, please avoid accessing data that is not yours, changing records, disrupting the service or publicly disclosing sensitive details before the issue can be reviewed.

Report the issue to victor.belobrov@proton.me with the subject “Security report”.

6. Certifications and standards

Belobrov Technologies does not currently claim ISO 27001 certification, SOC 2 attestation, PCI DSS certification, independent penetration-test certification or another formal security certification. The platform is developed using documented pilot-stage security and privacy controls and an internal OWASP-informed testing process. Relevant interoperability standards, including GS1 Digital Link, are being evaluated and will only be claimed as implemented or conformant after the applicable technical requirements have been completed and tested. Formal certification or independent assessment will only be stated after it has actually been obtained.

Belobrov Technologies
Independent software project · Republic of Moldova
PrivacyTermsCookiesSecurity