In transit
All traffic — public site, portals, API calls, media, webhooks — is served over TLS 1.3 with modern ciphers only. HSTS is enforced on our root domain. Legacy TLS 1.0 / 1.1 is disabled.
Security
PhoenixLearniVerse is built for regulated industries — finance, healthcare, government, energy. Here's what we do by default.
All traffic — public site, portals, API calls, media, webhooks — is served over TLS 1.3 with modern ciphers only. HSTS is enforced on our root domain. Legacy TLS 1.0 / 1.1 is disabled.
Databases, object storage, and backups are encrypted with AES-256. Encryption keys are managed by our cloud provider's KMS with automated rotation. Backups are encrypted separately.
Row-Level Security is enabled on every table containing user data. Role separation (learner / instructor / admin) is enforced server-side. Service-role keys never touch client code.
Card data is handled directly by Stripe and Paystack. We never see or store PANs. Webhooks are signature-verified before any state change.
API keys, provider secrets, and signing keys are stored in an encrypted secret manager, injected only into server functions, and never bundled to the browser.
Admin actions, certificate issuance, and payment events are logged with actor, timestamp, and IP for review.
Report a security concern: info@phoenixlearniverse.co.uk