Skip to main content
Trust & Security

Security by default.

How Sociora protects accounts, sessions, data in transit and the platform from common web security risks.

Security overview

Built to protect your community

University-grade controls, transparent hardening and clear reporting channels.

HTTPS everywhere

All HTTP requests are permanently redirected to HTTPS at the edge. We enforce Strict Transport Security (HSTS) on supported browsers.

Content Security Policy

A strict CSP limits script, style, connection, image, frame and form sources. Additional headers include X-Content-Type-Options, X-Frame-Options and a strict referrer policy.

Authentication & sessions

Session cookies are signed, HttpOnly and scoped to the application origin. We verify signatures on every protected request, and OAuth flows use state parameters and PKCE where supported.

University data residency

The platform is designed around university data-residency expectations, institutional governance workflows and clear audit trails.

Privacy by design

Member data stays yours and is never sold or shared with advertisers. Export records and reports whenever you need them.

Specialist Society boundaries

Optional specialist activity modules stay inside the Society that enables them. Sociora does not process wagering or cash settlements.

Reporting security issues

If you discover a vulnerability or suspicious behaviour, contact Sociora support. We will acknowledge receipt and share a timeline for resolution.

Last updated: 2 September 2026

Policies

Related governance pages

Trust your society tools

Join the pilot and see how Sociora keeps security, privacy and governance at the centre of the platform.