Security by constraint
- The server decides access, eligibility, and every match deadline.
- Every write request carries an idempotency key so retries cannot duplicate an action.
- Access checks follow relationships, never email addresses or other changeable fields.
- Logs must exclude messages, review answers, tokens, and direct personal data.
- Alerts cover service errors, scheduled jobs, and failed operator notifications.
Protect the most sensitive data first.
Chat, relationship records, safety reports, phone numbers, and private birth dates require encryption in transit and at rest. OTPs expire fast and must not enter logs.
Photos pass through validation, metadata removal, moderation, and access checks before release.
Account controls
Phone codes use send and attempt limits. Sessions expire and refresh. Signing out invalidates the device session. A keyed hash of the verified phone blocks two active accounts from using the same number, while domain records join on an internal identity ID.
Moderation and operator actions require named accounts and an audit record.
Report a security issue
Email hello@onematch.club with “Security report” in the subject. Include the affected page or feature, steps to reproduce, impact, and a safe proof.
Do not access another person’s account, disrupt service, run broad automated tests, or send private data in a report. OneMatch does not yet offer a bug bounty or safe-harbor program.