Back to Home

Security First

eSolia Courier is built with security at its core, following international standards to protect your data.

OWASP Top 10
ISO 27001/27002
FSA Guidelines

Courier relies on Nexus for core security features including OAuth, file storage, and share management.

View Nexus Security

Data Protection

All data is encrypted in transit with TLS 1.3 and at rest. Files stored securely in Cloudflare R2.

Access Control

OAuth 2.0 with PKCE authentication. Role-based permissions ensure users only access what they need.

Privacy by Design

Minimal data collection, passwordless authentication, and comprehensive audit trails.

Global Infrastructure

Powered by Cloudflare's edge network with built-in DDoS protection and rate limiting.

Compliance Ready

Designed to help you meet FSA cybersecurity guidelines and ISO 27001 requirements.

Secure Development

Built following OWASP Top 10 guidelines with regular security audits and code review.

OWASP Top 10 Compliance

We address each OWASP Top 10 risk category with specific security controls:

A01

Broken Access Control

OAuth 2.0 + PKCE, role-based access

A02

Cryptographic Failures

TLS 1.3, R2 encryption at rest

A03

Injection

Parameterized queries, CSP

A04

Insecure Design

Security-first architecture

A05

Security Misconfiguration

Secure defaults, strict headers

A06

Vulnerable Components

Regular audits, dependency scanning

A07

Auth Failures

Rate limiting, magic link auth

A08

Data Integrity

Nexus HMAC signing, audit logs

A09

Logging Failures

Comprehensive security logging

A10

SSRF

No external requests

Want to know more about our security implementation?

Report security vulnerabilities to security@esolia.co.jp

security.txt