Account protection
The system uses secure sessions, email verification and access controls to limit data to the appropriate user.
Users should use strong passwords, protect their login email and sign out from devices they no longer use.
Payment security
SePay QR webhooks are verified with HMAC-SHA256, replay-resistant timestamps and checks for amount, receiving account and payment code before marking payment as paid.
SePay Gateway IPN uses a dedicated secret to authenticate card payment notifications. Transactions and row locks prevent credits or course enrollments from being applied twice.
Operations and audit
Payments store a unique `providerTransactionId` and `rawPayload` to support basic audit, transaction reconciliation and provider retry handling.
Billing administrators should only confirm manual transfers after checking the bank statement, amount and payment memo against the pending payment.
Report an issue
If you discover a vulnerability or unusual behavior involving accounts, payments or data, contact support@scalelabsai.org.
Please do not exploit, publicly disclose or access data you are not authorized to view while reporting an issue.
Contact the ScaleLabsAI team at support@scalelabsai.org.