Security
How we protect your data
A transparent overview of our technical and organizational security measures - without marketing promises we cannot keep.
Encryption of credentials
Bot tokens are stored exclusively AES-256-GCM encrypted - with a dedicated initialization vector per value, a separately stored auth tag, and key versioning. Tokens are decrypted exclusively by the instance manager, never returned via the API, never displayed in the frontend, and never written to logs.
A hash of the token ensures that a token is always assigned to exactly one account.
Passwords & login
Passwords are hashed with scrypt (an individual salt per account) and never stored in plain text, logged, or sent by email. During registration, passwords are checked against a list of commonly used passwords.
After several failed attempts, an account is temporarily locked to make automated guessing harder.
Two-factor authentication
You can additionally protect your account with TOTP-based two-factor authentication (compatible with common authenticator apps). Backup codes are stored only as hashes and shown to you exactly once during setup.
Session management
Sessions are managed server-side and can be revoked individually or entirely at any time. Sensitive actions such as token changes, email changes, or account deletion require you to confirm your credentials again (re-authentication).
Server-side permission checks
Every action in the dashboard is checked on the server against your actual Discord permissions or your account role - the frontend is display only and never the sole access control.
Customer bots kept separate
Custom bot instances run separately from the main bot. Each instance has its own error boundaries: if one instance crashes, other customers' bots keep running.
Secure payments
Payment processing runs entirely through Stripe. For subscriptions and purchases, Cordavix does not store any credit card or bank details - premium entitlements are also checked server-side on every request, never only in the frontend. Affiliate payout details (account holder, PayPal address, IBAN, BIC) are stored exclusively AES-256-GCM encrypted.
Affiliate payout details (account holder, IBAN/BIC, or PayPal address) are stored exclusively AES-256-GCM encrypted.
Audit logs
Security-relevant changes to servers and accounts are logged traceably (user, action, timestamp). Sensitive values such as passwords or tokens never appear in the log.
Data export & account deletion
You can request an export of your account data yourself at any time - based exclusively on an allowlist, never including tokens, passwords, or keys. You can request account deletion yourself; it takes effect after a revocation period, after which your data is anonymized or deleted unless a statutory retention obligation applies.
Found a security vulnerability?
We are grateful for reports about security vulnerabilities. Please report weaknesses responsibly through our contact form instead of making them public - we will take care of them promptly.