HTTPS و TLS
دامنههای تولید با HTTPS، گواهی خودکار و HSTS ارائه میشوند تا ارتباط مرورگر و سرویس در مسیر محافظت شود.
گذرواژه هششده
گذرواژه خام ذخیره نمیشود؛ سرور از هش گذرواژه برای بررسی ورود استفاده میکند.
تفکیک نقشها
مشتری و کارمند حساب، توکن و مسیرهای ورود جداگانه دارند.
کد یکبارمصرف
ورود و بازیابی حساس میتواند با کد یکبارمصرف ایمیل یا پیامک محافظت شود.
محدودیت درخواست
ورود، کد یکبارمصرف و فرمهای عمومی در برابر تکرار سریع درخواست محدود میشوند.
احراز هویت و سابقه
جابهجایی پول به وضعیت احراز هویت وابسته است و اقدامات عملیاتی مهم سابقه قابل بررسی دارند.
HTTPS and TLS
Production domains use HTTPS, automatically managed certificates, and HSTS to protect browser-to-service traffic in transit.
Hashed passwords
Raw passwords are not stored; the server verifies logins against password hashes.
Separated roles
Customers and Staff use separate accounts, tokens, and authentication routes.
One-time codes
Sensitive login and recovery flows can be protected by email or SMS one-time codes.
Rate limits
Login, one-time-code, and public-form requests are limited against rapid repetition.
KYC and records
Money movement is gated by KYC status, and important operational actions produce reviewable records.