Back to Login

Security at DigiAbility Community

An overview of how we protect accounts and data across the platform.

Authentication

Sign-in uses RS256-signed JWT access tokens with a short 15-minute lifetime, paired with a separate refresh token for staying signed in. Only the identity service holds the private signing key — every other service can verify a token but never issue one.

Credential storage

Passwords are hashed, never stored or logged in plain text. Refresh tokens are stored as one-way SHA-256 hashes, so the raw token itself never sits in our database. Admin accounts can additionally enable two-factor authentication from Settings → Security.

Access control & auditing

Admin actions are role-gated and recorded in an audit log, so changes to users, groups, and content can be traced back to who made them and when.

Ongoing hardening

Security work continues on an ongoing basis, including rate limiting, input validation, and periodic review of how tokens and personal data are stored and transmitted.

Report a concern

If you believe you've found a security issue, please email support@digiability.org with details so we can investigate promptly.