Account credentials
- Passwords are hashed with bcrypt before they are stored.
- New passwords must meet length and complexity requirements.
- Password-reset and email-verification tokens are random, expire, and are stored as hashes.
This page describes controls that are implemented in the application today.
These controls reduce risk but cannot guarantee absolute security. SurveyMint does not claim SOC 2 or ISO 27001 certification on this page. A feature description is not a substitute for your own security, privacy, or regulatory review.
Send a concise description, affected page, reproduction steps, and potential impact to hi@surveymint.io. Do not access or alter another person's data while investigating.
Please do not include passwords, session tokens, private survey answers, or other secrets in the initial report.