🛡️ Security at OHS Social

This page is generated live, right now, from the running site — it is not a marketing page. Each item below was re-checked when you loaded this page, and anything currently failing is shown as failing.

14 of 14 checks passing · external checks last run 21h ago

What's in place
🔒

Encrypted (TLS)

This page was served over an encrypted TLS connection, so traffic between your browser and the site cannot be read in transit.

Active
📜

Valid certificate

The certificate for this site verified successfully against a trusted root, issued by Let's Encrypt, and is valid for another 86 days.

Active
🛡️

HSTS enforced

Strict-Transport-Security is sent on HTTPS responses, so browsers refuse to fall back to unencrypted HTTP for six months after their first visit.

Active
📹

Cams on Cloudflare® Realtime

Cam rooms run on Cloudflare® Realtime services — Cloudflare relay servers carry cam traffic for anyone whose network blocks a direct peer-to-peer connection. Confirmed by a live credential check against the Realtime API, not just a saved setting.

Active
🗄️

Data store sealed

A file was placed inside the data directory and then requested over the web; the server refused to serve it (HTTP 403), confirming member data is not readable from the internet.

Active
🔑

Hashed passwords

Passwords are stored as bcrypt hashes and never in readable form. Nobody — including the site operator — can retrieve your password; it can only be reset.

Active
🎫

CSRF protected

Every form that changes data carries a single-use token tied to your session, so another site cannot make your browser act on your behalf.

Active
🧼

XSS filtered

All member-supplied text is HTML-escaped before display, and rich formatting is rebuilt from a fixed whitelist rather than passed through — raw HTML from a post can never execute.

Active
🧱

Hardened headers

Responses set X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and a Content-Security-Policy, limiting sniffing, clickjacking, referrer leakage and unexpected camera or microphone access.

Active
🍪

Secure sessions

Session cookies are HttpOnly and SameSite, marked Secure on HTTPS, and can be revoked per device from your account settings.

Active
⏱️

Abuse limits

Logins, registrations and other sensitive actions are rate limited per address to blunt brute-force and automated abuse.

Active
📎

Screened uploads

Uploaded files are checked by inspecting their actual contents rather than trusting the filename, restricted to a small image whitelist, and stored under a newly generated random name.

Active
🔐

Two-factor available

Accounts can enable app-based two-step verification (TOTP) from account settings.

Active
💾

Automatic backups

Every data file is snapshotted automatically on a daily schedule, before any maintenance task is allowed to touch it.

Active
What we don't claim

Plenty of sites display seals they never earned. So, plainly:

  • OHS Social is not PCI DSS, SOC 2, ISO 27001 or HIPAA certified, and does not claim to be. Those require paid third-party audits.
  • We do not display purchased "verified secure" seals. Every badge on this site corresponds to a check listed above.
  • Payments, where they occur, are handled by the payment provider — card numbers are never entered into or stored by this site.
  • No system is perfectly secure. Use a password you don't reuse anywhere else, and turn on two-step verification.
Found a vulnerability?

Please report it to support@ourhangoutspace.com rather than disclosing it publicly, and give us a reasonable window to fix it. Reports are welcome and taken seriously.