Infrastructure Security &
Zero-Knowledge Defense.
How we engineer, isolate, and protect your account credentials, active sessions, and direct communications against modern web threats.
Strict TLS 1.3 & HSTS
All HTTP and WebSocket transmissions are encrypted using modern TLS 1.3 with Perfect Forward Secrecy (PFS), blocking packet sniffing and man-in-the-middle exploits.
One-Way Hash Derivation
Passwords are never stored in readable format. We enforce high-factor salted Argon2/Bcrypt key stretching, rendering offline brute-force attacks computationally infeasible.
Active Session Revocation
Inspect every active browser or mobile session with IP and timestamp metadata. Remotely terminate unrecognized logins with a single tap from Account Settings.
Defense-in-Depth Mechanisms
Automated Media EXIF Stripping
Raw camera photos frequently carry embedded GPS coordinates, camera serial numbers, and home timestamps. Our ingestion workers automatically scrub this metadata before images are saved to disk, preserving physical privacy.
Sliding Window Rate Limiting
Distributed Redis token buckets throttle suspicious velocity bursts: authentication attempts, password resets, follower queries, and message broadcasts are capped to halt credential stuffing.
Responsible Vulnerability Disclosure
We welcome security researchers and ethical hackers who assist in keeping FriendsBook and AXIONIK infrastructure safe. If you discover a vulnerability:
- Email detailed reproduction steps and proofs-of-concept to
security@friendsbook.co.in. - Do not attempt to view, alter, or destroy other users' private accounts or personal media.
- Grant our engineering team a reasonable 14-day remediation window prior to public disclosure.
- We acknowledge valid submissions within 24 business hours and provide official security researcher recognition.