Authenticated workspaces
Private reports, messages and documents are delivered through signed, secure browser sessions. Administrative and client permissions are checked by the server, not trusted to browser controls.
SinoSource separates public research from private client workspaces, limits who can reach client records, and treats uploaded evidence as untrusted until it has passed the applicable checks. This page explains the controls and the limits without claiming certifications we do not hold.
Private reports, messages and documents are delivered through signed, secure browser sessions. Administrative and client permissions are checked by the server, not trusted to browser controls.
Client files use random storage names outside the public web root and are returned only through an ownership-checked download handler. Uploads are checked by size, extension, detected content, file signature and archive-expansion limits before malware scanning.
Database backups are encrypted before off-site transfer. Recovery procedures include an isolated restore workflow so a backup is tested before it is trusted as recoverable.
Marketing pages and public research are intentionally separated from authenticated client and operator actions. Public pages may load optional analytics or support tools only after consent.
Authenticated areas use restrictive caching and do not load optional marketing analytics or live-chat code. Sensitive actions are authorised again at the API boundary.
Every administrator uses a named account. Production sign-in requires TOTP multi-factor authentication; an unenrolled account can enter only the short-lived enrolment flow. Recovery codes are one-use, sessions are individually revocable, and successful sign-ins generate an email alert.
New passwords are checked against known breach data through the k-anonymous Pwned Passwords range protocol. Only the first five characters of a SHA-1 hash are sent; the password and complete hash do not leave SinoSource.
Card details are handled by Stripe. SinoSource receives subscription and payment status; it does not store full payment-card numbers or CVC values.
Where an AI-assisted feature is used, prompts are routed through controlled server-side services. Client data should be minimised to what the requested task needs, and AI output is not treated as verified evidence by itself.
We collect the contact, onboarding, supplier, evidence and operational information needed to deliver the agreed service. The full categories and lawful bases are described in the Privacy Policy.
Self-service account deletion removes the individual sign-in identity and disconnects it from client workspaces. It does not silently erase organisation-owned or shared reports, documents, evidence, sourcing activity, or financial records. Workspace erasure is a separate, authority-checked request, and retention periods and legal exceptions are stated in the Privacy Policy.
Hosting, payments, email, account sign-in, optional public-site analytics/support and AI-assisted processing depend on disclosed service providers. The current list and international-transfer information appear in the Privacy Policy.
Do not share portal access, reuse passwords from other services, or send client access information through public channels. Report suspected access immediately.
Remove unrelated personal data and secrets from supplier documents before uploading. Do not upload executable software, password databases or documents you are not authorised to share.
Security controls protect the workspace; they do not make a supplier claim true. Testing, contracts, banking verification and regulatory decisions remain separate checks before funds move.
The platform has not yet completed SOC 2, ISO 27001 or an independent penetration test. Automated release checks and operator review reduce risk; they are not a substitute for external assurance.
The release contains enforced TOTP enrolment, replay protection, one-use recovery codes and login alerts. Each production administrator must still complete enrolment on a real authenticator and store the recovery codes safely; the owner health panel reports the live enrolment count.
Evidence uploads fail closed when validation or configured malware scanning cannot establish an acceptable result. The operator health panel reports whether the scanner and outside-root vault are active.
Email info@getsinosource.com with “Security report” in the subject. Include the affected URL, when you observed the issue and reproducible steps. Do not include passwords, private keys, full payment details or unnecessary client data. We will preserve relevant records, triage the report, contain confirmed exposure and notify affected parties or authorities where legally required.
Last reviewed: 14 August 2026. This page describes operational controls; it is not an independent audit report or certification. Material changes to processors or handling practices are reflected in the Privacy Policy.