Skip to content

GoRefer Trust Center

Network Security

Updated September 2026

About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.

GoRefer's application limits request rates and sends security headers with its responses. Protection at the network edge, private networking and DNS controls depend on our hosting providers; this page lists them, and details for each are available on request.

The header descriptions below summarize how GoRefer's headers are set up. You can check the headers any page sends with a tool such as securityheaders.com, and request details of the controls our providers manage.

DDoS mitigation
WAF configuration
HTTPS transport
Rate Limited
HSTS header

Edge Security: DDoS Mitigation & WAF

Details on request

Updated September 2026

Edge providers can supply DDoS mitigation, firewall rules and bot controls. Details of which ones are turned on, the hostnames they cover and any exceptions are available on request.

DDoS Protection

  • Network-layer mitigation

    Service, coverage and limits: details on request

  • Application-layer protection

    Detection, challenge and blocking rules: details on request

  • Provider network

    Edge setup and the hostnames routed through it: details on request

  • Peak-period readiness

    Tax-season capacity planning and rule tuning: details on request

Web Application Firewall (WAF)

  • Managed WAF rules

    Active rules and exceptions: details on request. No rule set blocks every attack

  • Custom rules

    Any custom rules and the pages they cover: details on request

  • Rule updates

    How rules are updated and tested: details on request

  • Bot management

    Bot protection, thresholds and false-positive handling: details on request

Network Architecture & Segmentation

Updated September 2026

VPC & Network Isolation

  • Network placement and public entry points: details on request

  • Database connectivity and network separation: details on request

  • Firewall rules and open ports: details on request

  • Which networks can reach the database: details on request

  • Private and public connections between services: details on request

Traffic Inspection & Monitoring

  • Network flow logging and retention: details on request

  • Outbound-traffic detection and alerts: details on request

  • DNS logging and detection rules: details on request

  • Network intrusion detection: details on request

  • Load-balancer log retention: details on request

API Rate Limiting

Updated September 2026

GoRefer limits request rates to protect against brute-force attacks, data exfiltration attempts and API abuse. Sign-in and account-recovery requests have their own limits. Other limits vary by feature; there is no single limit for every part of the API.

AreaRate LimitAction on BreachWhy
Sign-in and account recoveryAttempt limits within a time windowRate-limit or lockout responseReduce brute-force and recovery abuse
Gio operationsCredits and per-feature limitsRequest refused when applicable limits are reachedManage metered operations
Exports and other API requestsSet per featureDepends on the featureDetails on request

Discuss API access requirements

Contact security@gorefer.io to discuss network and integration requirements, including whether IP restrictions or higher rate limits are available for your account.

HTTP Security Headers

Updated September 2026

GoRefer sends security headers from its website, web app and API. Values and exceptions differ by page, including public embeds. These headers reduce specific browser risks, and you can check the headers any page sends yourself.

HeaderValue / SettingProtection ProvidedStatus
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preloadForces HTTPS for 2 years. The preload flag makes the domain eligible for browsers' built-in HTTPS lists; it does not guarantee the domain is on them.Enforced
Content-Security-PolicyConfigured — restricts script, style, and media sourcesRestricts allowed content sources to reduce some script-injection risks; policy details vary by page.Enforced
X-Frame-OptionsFrame policy set per pageRestricts framing on covered pages. Public embeds have different requirements.Enforced
X-Content-Type-OptionsnosniffPrevents browsers from MIME-sniffing responses — stops content-type confusion attacks.Enforced
Referrer-Policystrict-origin-when-cross-originPrevents the full URL (including query parameters) from being leaked to external sites via the Referer header.Enforced
Permissions-PolicyPermissions set per pageDisables browser APIs that GoRefer does not use — prevents browser feature hijacking.Enforced
Cross-Origin-Opener-PolicyOpener policy set per pageIsolates the GoRefer browsing context — prevents cross-origin window attacks.Enforced

DNS Security

Updated September 2026

Email Authentication

  • SPF records for each sending domain: details on request

  • DKIM for mail from our email provider: details on request

  • DMARC policy and reporting: details on request

  • BIMI (brand logo in the inbox): not yet reviewed

Certificate Management

  • TLS certificates managed via a trusted CA

  • Certificate renewal and expiry alerts: details on request

  • Certificate Transparency records are publicly searchable

  • Certificate mis-issuance alerts: details on request

Domain Security

  • DNSSEC: details on request

  • Registrar access and MFA: details on request

  • Subdomain ownership and monitoring: details on request

  • CAA records and approved certificate authorities: details on request