Our approach
Authorization and permission checks run on the server. The public API returns only an explicitly allowlisted set of fields. Request rate limits and request-size limits apply, and the connection to ecoesep.kz is protected with TLS.
Pilot boundaries
Some protections are enabled in stages. While the workspace is open for testing, do not enter real confidential data. No formal certifications are claimed at the pilot stage.
Report a vulnerability
Write to ecoesep@gmail.com with the subject "Security". Describe reproduction steps and do not publish details before our reply. We appreciate responsible disclosure.