TLS + secure cookies
All production environments enforce HTTPS, `COOKIE_SECURE`, and strict environment validation so tokens never travel in plain text.
Dokodo ships with audited auth, CSP, rate limiting, and audit logging. We publish the checklist so you always know how data is protected.
Checking your workspace…
Questions? Email hello@dokodo.app.
These controls shipped during the December 2024 security audit and now gate every production deploy.
All production environments enforce HTTPS, `COOKIE_SECURE`, and strict environment validation so tokens never travel in plain text.
Next.js CSP plus Helmet headers block unexpected scripts, frames, and cross-origin requests per docs/ops/32-production-security-checklist.
API traffic is throttled with Redis-backed counters that persist across restarts to contain brute-force attempts.
Users can see active sessions, revoke access, and every sensitive action (password, deletion) lands in AuditLog with 90-day retention.
Security is not a single feature—it is a set of ongoing rituals, all documented in ops runbooks.
We document detect → assess → contain → notify workflows so the team can act quickly if something looks off.
The ops checklist covers uptime monitors, error tracking, and daily Postgres backups with 30-day retention.
JWT secrets require 48+ bytes entropy and rotate quarterly; database connections enforce SSL (`sslmode=require`).
New accounts verify email and password changes revoke all active sessions to prevent takeovers.
Read the full checklist at docs/ops/32-production-security-checklist.
Security is iterative. These items are in flight as we expand paid plans.
Integrate antivirus scanning (ClamAV or hosted) before accepting new media uploads.
Redis-backed tracking of failed logins per identity to complement throttling.
Optional TOTP for Pro/Team accounts once subscription billing goes live.
CI-enforced Dependabot/Snyk policies for both frontend and backend packages.
We are happy to walk through architecture, SOC 2 planning, or custom terms. Email hello@dokodo.app and we will reply within one business day.
Checking your workspace…