Legal

Security
practices.

How we protect your data, your keys, and your customers' OTPs.

Last updated: 2026-01-15

1. Encryption

All API traffic uses TLS 1.2 or higher. Internal traffic between services runs over a private network. Data at rest is encrypted with AES-256.

2. Authentication

API keys are hashed with bcrypt (cost 12). Raw keys are shown only once at creation. Dashboard access uses JWT with 15-minute access tokens and refresh-token rotation.

3. Rate limiting

Per-client sliding window of 100 requests/minute. Burst protection at the edge. Suspicious patterns trigger temporary holds and an alert.

4. Infrastructure

Production runs on hardened Linux hosts inside Turkmenistan. Database backups are encrypted, replicated, and tested weekly.

5. Access control

Engineer access to production is gated through SSH certificates with 12-hour TTL. All admin actions are logged and reviewed weekly.

6. Vulnerability disclosure

Found a security issue? Email security@ugrat.com. We acknowledge within 24 hours and aim to remediate critical issues within 7 days.

7. Incident response

We notify affected customers within 72 hours of confirming a security incident, with a description, impact, and the remediation steps taken.

8. Compliance

We follow ISO 27001 control objectives and align our practices with GDPR principles where customer data flows internationally.