Security.
If you have found a weakness in MoveURAS, tell us. A person reads every report and replies to you.
How to tell us
Write to support@moveuras.com with “Security” in the subject. Say what you found, where, and how to see it again. Please do not send anyone else's personal data, even if you could reach it.
This covers moveuras.com and its subdomains: the partner panel, the team's console, the demo, the chat and the API, and the MoveURAS app.
What we ask of you
- Look only at your own account and your own data.
- Do not change, delete or download anything that is not yours, and do not slow the service down for anyone else.
- Testing beyond ordinary use of the site needs our written permission first, as the terms say. Ask, and tell us what you want to try.
- Give us a reasonable time to fix a problem before you tell anyone else about it.
How it is built
- There are no passwords. Every account signs in with its email address and a six-digit code sent to it; on the panels the code expires in ten minutes.
- Every page is served over HTTPS only, with a Content Security Policy that names each origin a page may load from.
- The partner panel and the console carry no analytics and no script of anyone else's: a script on a page that holds a session is a way to take the session.
- A business never sees who redeemed. It sees a code for that person that is different at every business.
- Our servers are our own, in Germany, with Cloudflare in front of them. The privacy notice says what is kept and for how long.
The machine-readable version of this page is at /.well-known/security.txt.