Security principles
Security practices and responsible disclosure.
Security practices U Framework applies to its own systems and the systems it builds. We do not claim certifications we do not hold.
Application security
- Input is validated at every trust boundary with schemas; uploads are type-checked by their bytes, size-limited and never executed or served as HTML.
- Authentication uses salted bcrypt password hashes and signed, HTTP-only,
SameSitesession cookies with short lifetimes. - Authorization is enforced on the server for every action, never only in the interface.
- Responses carry security headers:
X-Content-Type-Options,X-Frame-Options,Referrer-Policy,Strict-Transport-Securityand a restrictivePermissions-Policy.
Secrets
Secrets live in environment variables or managed secret stores, never in source control or client bundles.
Dependencies
Dependencies are kept current, pinned through lockfiles and audited.
Data
Personal data is minimized, encrypted in transit and stored only as long as needed. See the privacy policy.
Responsible disclosure
If you believe you have found a security issue in a U Framework system, please report it through the contact page with the project type "Other" and the word "Security" in the description. Please give us reasonable time to investigate before any public disclosure. We will acknowledge valid reports and keep you informed.