Security Architecture

Full technical disclosure of our security stack. If you're a procurement team or enterprise buyer, this page is for you.

Encryption Standard

AES-256 at rest across all stored data. TLS 1.3 enforced in transit with no fallback to older protocols. Supabase row-level security (RLS) ensures users can only access their own data — even at the database query level.

Access Control

Multi-factor authentication required on all accounts. Session timeouts enforced. IP logging on every authenticated request. Failed login attempt monitoring with automatic lockout.

Network Security

All products proxied through Cloudflare WAF. Geographic access controls block high-risk origin countries at three layers: Supabase Edge Function, Cloudflare WAF rule, and frontend runtime check. Content Security Policy headers enforced on all pages.

Data Sourcing

Tariff data sourced directly from USITC public API (hts.usitc.gov) — no third-party data brokers. Grant data sourced from Grants.gov public database. Classification research cross-referenced against CBP CROSS binding rulings database (cbp.gov/trade/rulings).

Incident Response

In the event of a suspected security incident, affected users will be notified within 72 hours via the email address on their account. Full incident reports available on request.

Operational Security Posture

Desert Oasis Digital LLC was founded by a former Army Civilian Intelligence Officer with specialized training in OPSEC, Technical Surveillance Mitigation, and High-Threat Tradecraft. Security is not a feature — it is the foundation.

Report a Vulnerability

Responsible disclosure: will@desertoasisdigital.com
We take all reports seriously and respond within 48 hours.

Linked Data Sources