GoRefer Trust Center
Network Security
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
GoRefer's application limits request rates and sends security headers with its responses. Protection at the network edge, private networking and DNS controls depend on our hosting providers; this page lists them, and details for each are available on request.
The header descriptions below summarize how GoRefer's headers are set up. You can check the headers any page sends with a tool such as securityheaders.com, and request details of the controls our providers manage.
Edge Security: DDoS Mitigation & WAF
Updated September 2026
Edge providers can supply DDoS mitigation, firewall rules and bot controls. Details of which ones are turned on, the hostnames they cover and any exceptions are available on request.
DDoS Protection
Network-layer mitigation
Service, coverage and limits: details on request
Application-layer protection
Detection, challenge and blocking rules: details on request
Provider network
Edge setup and the hostnames routed through it: details on request
Peak-period readiness
Tax-season capacity planning and rule tuning: details on request
Web Application Firewall (WAF)
Managed WAF rules
Active rules and exceptions: details on request. No rule set blocks every attack
Custom rules
Any custom rules and the pages they cover: details on request
Rule updates
How rules are updated and tested: details on request
Bot management
Bot protection, thresholds and false-positive handling: details on request
Network Architecture & Segmentation
Updated September 2026
VPC & Network Isolation
Network placement and public entry points: details on request
Database connectivity and network separation: details on request
Firewall rules and open ports: details on request
Which networks can reach the database: details on request
Private and public connections between services: details on request
Traffic Inspection & Monitoring
Network flow logging and retention: details on request
Outbound-traffic detection and alerts: details on request
DNS logging and detection rules: details on request
Network intrusion detection: details on request
Load-balancer log retention: details on request
API Rate Limiting
Updated September 2026
GoRefer limits request rates to protect against brute-force attacks, data exfiltration attempts and API abuse. Sign-in and account-recovery requests have their own limits. Other limits vary by feature; there is no single limit for every part of the API.
| Area | Rate Limit | Action on Breach | Why |
|---|---|---|---|
Sign-in and account recovery | Attempt limits within a time window | Rate-limit or lockout response | Reduce brute-force and recovery abuse |
Gio operations | Credits and per-feature limits | Request refused when applicable limits are reached | Manage metered operations |
Exports and other API requests | Set per feature | Depends on the feature | Details on request |
Discuss API access requirements
Contact security@gorefer.io to discuss network and integration requirements, including whether IP restrictions or higher rate limits are available for your account.
HTTP Security Headers
Updated September 2026
GoRefer sends security headers from its website, web app and API. Values and exceptions differ by page, including public embeds. These headers reduce specific browser risks, and you can check the headers any page sends yourself.
| Header | Value / Setting | Protection Provided | Status |
|---|---|---|---|
Strict-Transport-Security | max-age=63072000; includeSubDomains; preload | Forces HTTPS for 2 years. The preload flag makes the domain eligible for browsers' built-in HTTPS lists; it does not guarantee the domain is on them. | Enforced |
Content-Security-Policy | Configured — restricts script, style, and media sources | Restricts allowed content sources to reduce some script-injection risks; policy details vary by page. | Enforced |
X-Frame-Options | Frame policy set per page | Restricts framing on covered pages. Public embeds have different requirements. | Enforced |
X-Content-Type-Options | nosniff | Prevents browsers from MIME-sniffing responses — stops content-type confusion attacks. | Enforced |
Referrer-Policy | strict-origin-when-cross-origin | Prevents the full URL (including query parameters) from being leaked to external sites via the Referer header. | Enforced |
Permissions-Policy | Permissions set per page | Disables browser APIs that GoRefer does not use — prevents browser feature hijacking. | Enforced |
Cross-Origin-Opener-Policy | Opener policy set per page | Isolates the GoRefer browsing context — prevents cross-origin window attacks. | Enforced |
DNS Security
Updated September 2026
Email Authentication
SPF records for each sending domain: details on request
DKIM for mail from our email provider: details on request
DMARC policy and reporting: details on request
BIMI (brand logo in the inbox): not yet reviewed
Certificate Management
TLS certificates managed via a trusted CA
Certificate renewal and expiry alerts: details on request
Certificate Transparency records are publicly searchable
Certificate mis-issuance alerts: details on request
Domain Security
DNSSEC: details on request
Registrar access and MFA: details on request
Subdomain ownership and monitoring: details on request
CAA records and approved certificate authorities: details on request