HTTPS everywhere
All HTTP requests are permanently redirected to HTTPS at the edge. We enforce Strict Transport Security (HSTS) on supported browsers.
How Sociora protects accounts, sessions, data in transit and the platform from common web security risks.
Security overview
University-grade controls, transparent hardening and clear reporting channels.
All HTTP requests are permanently redirected to HTTPS at the edge. We enforce Strict Transport Security (HSTS) on supported browsers.
A strict CSP limits script, style, connection, image, frame and form sources. Additional headers include X-Content-Type-Options, X-Frame-Options and a strict referrer policy.
Session cookies are signed, HttpOnly and scoped to the application origin. We verify signatures on every protected request, and OAuth flows use state parameters and PKCE where supported.
The platform is designed around university data-residency expectations, institutional governance workflows and clear audit trails.
Member data stays yours and is never sold or shared with advertisers. Export records and reports whenever you need them.
Optional specialist activity modules stay inside the Society that enables them. Sociora does not process wagering or cash settlements.
If you discover a vulnerability or suspicious behaviour, contact Sociora support. We will acknowledge receipt and share a timeline for resolution.
Last updated: 2 September 2026
Policies
Join the pilot and see how Sociora keeps security, privacy and governance at the centre of the platform.