Transport security
The production application is served over HTTPS and sends strict browser security headers (HSTS, CSP).
Data minimization
Participant sessions use pseudonymous tokens and temporary connection IDs.
Account protection
Creator passwords are stored only as salted, one-way hashes with secure HTTP-only cookies in production.
WebSocket Rate-Limiting
Action quotas prevent flooding on answers, reactions, and live room control commands.
Media isolation
Uploads use restricted object-storage write access and controlled public delivery for activity images.
Managed infrastructure
Application data and media rely on MongoDB and AWS services with access restricted to the server environment.
Application and account security
- Passwords are salted and hashed; QuizSpire never stores plain-text passwords.
- Production authentication cookies are HTTP-only, secure, and use SameSite protections.
- Creator-only routes and resources validate ownership and RBAC permissions on the server.
- Secrets such as database credentials and AWS keys are managed in server environment variables.
- Uploaded files are validated by MIME type and strict size limits before acceptance.
Live session protection
- Each live activity receives an unpredictable internal identifier and a temporary join PIN.
- Hosts control lobby locking, session progression, and kicking disruptive participants.
- Participant resume tokens are treated as credentials and are not shown in public reports.
- Server-side checks determine whether a player can join, answer, resume, or control a session.
Infrastructure and media
QuizSpire is hosted on AWS EC2, with application records stored in MongoDB and media stored in Amazon S3. Public activity images may be delivered through CloudFront.
Access to production infrastructure is limited to administrative needs. Logs may record operational metadata needed to diagnose reliability and security problems, but secrets and passwords are never deliberately logged.
Security limitations
No online service can guarantee absolute security or uninterrupted availability. Creators should not use QuizSpire to collect highly sensitive information such as payment-card data, government identifiers, medical records, passwords, or private access tokens.
Report a vulnerability
Responsible disclosure
Email support@quizspire.com with the affected URL, reproducible steps, impact, and supporting evidence.
We aim to acknowledge credible security reports within two business days.
Privacy and deletion
Security practices work alongside the Privacy Policy. Account owners and participants can use the verified deletion process to request removal of personal information.
Include the relevant game PIN or approximate time of the issue, but never send a password.