JoeLog Home

Security

Security & Responsible Disclosure

Last reviewed: September 5, 2026

Firearm locations, identity records, documents, and Form 4473 responses can create serious risk if exposed. JoeLog uses layered application controls, but this page is a factual summary rather than a certification or guarantee.

Implemented controls

  • Passwords are hashed with Argon2id, and authentication uses opaque server-side sessions that can be revoked.
  • Email verification, CSRF protection, and optional TOTP multi-factor authentication protect account workflows.
  • Organization membership and roles scope tenant access, with organization identifiers carried through tenant database relationships.
  • Sensitive Form 4473 response payloads use application-level encryption.
  • Documents use private S3-compatible object storage, server-side encryption requests, and integrity verification.
  • Browser responses apply a content security policy, referrer policy, MIME-sniffing prevention, and frame denial.

Limits of this statement

The controls above do not establish universal encryption for all data. JoeLog does not claim a completed penetration test, independent security audit, certification, malware scanning, tested disaster recovery, guaranteed backups, uptime commitment, or vulnerability-remediation deadline.

JoeLog is not currently an ATF-compliant electronic recordkeeping system and must not be used as one.

Reporting a vulnerability

Report suspected vulnerabilities to aubergine@joelog.com with "Security report" in the subject. Describe the affected feature, potential impact, and non-sensitive reproduction steps. Formal scope, safe-harbor language, acknowledgement targets, response commitments, disclosure timelines, reporter credit, and bounty terms are not yet published. Their absence is not permission to test the service.

Do not email credentials, identity documents, firearm locations, Form 4473 data, live exploit payloads, or other sensitive evidence. Ask for approved transfer instructions first.

Testing boundaries

Unauthorized testing is prohibited. Do not access or attempt to access another user's account or data; alter records; download documents; perform social engineering; run broad automated scans; introduce malware; evade access controls; or degrade availability. Do not test against third-party providers.

If sensitive information is encountered accidentally, stop immediately. Do not retain, copy, share, or further inspect it. Email only the non-sensitive details needed to identify what happened, then wait for approved transfer instructions.