Enhancing Security at Punch-in
Essential Features for Modern Applications
A comprehensive guide to implementing robust security measures for applications.
1. Encrypted Passwords
Storing passwords securely is a fundamental aspect of application security. Password breaches can lead to devastating consequences, making encryption a non-negotiable feature.
Best Practices for Password Encryption
- Use strong hashing algorithms like bcrypt, PBKDF2, or Argon2.
- Salt passwords to ensure unique hashes.
- Periodically rehash passwords with updated algorithms.
2. State-of-the-Art TLS Encryption
Transport Layer Security (TLS) ensures data integrity, confidentiality, and authentication, preventing eavesdropping and man-in-the-middle attacks.
TLS Best Practices
- Enforce TLS 1.3 for enhanced security and performance.
- Use strong cipher suites such as AES-256-GCM or ChaCha20-Poly1305.
- Enable HTTP Strict Transport Security (HSTS).
- Regularly update certificates using trusted CAs.
3. Separate Environments
Creating secure environments minimizes the attack surface of your application, protecting sensitive data and reducing exposure to vulnerabilities.
Key Strategies
- Apply the Principle of Least Privilege (PoLP).
- Use containerization tools like Docker or Kubernetes.
- Store secrets in environment variables instead of hardcoding.
- Configure secure defaults, such as strong password policies.
- Separated environments allows for great reliability and SLA.
4. DDoS Protection and Edge Filtering
Punch-in is delivered through a global content delivery network backed by a tier-one cloud provider. Every request is inspected and absorbed at the network edge before it can reach the application, so volumetric attacks are stopped far away from your data.
What This Means in Practice
- Always-on protection against network and transport layer (L3/L4) distributed denial-of-service attacks, including SYN floods, UDP reflection and other volumetric attacks.
- Malformed and known-bad traffic is dropped automatically at the edge, without any action required from us or from you.
- Requests are served from edge locations close to your users, so a surge in traffic in one region cannot degrade service elsewhere.
- Attack mitigation is continuous and scales with the size of the provider's global network, not with the size of any single server.
5. Managed Firewall and Rate Limiting
The application is only reachable through a managed API gateway. There are no publicly addressable servers, no open administrative ports, and no direct path from the internet to the database or file storage.
Layers of Defence
- All traffic enters through a single, managed gateway that enforces request throttling and burst limits to protect against abuse and brute-force attempts.
- Application components run inside private networks with firewall rules that deny all inbound connections by default.
- Database and file storage are attached only to the compute that needs them and are never exposed on the public internet.
- Outbound network access from the application is restricted, limiting the impact of any compromised component.
6. Serverless Compute and Automatic Patching
Punch-in runs on serverless infrastructure. There are no long-lived servers for us to harden, patch or forget about; each request runs in a short-lived, isolated execution environment.
Why This Matters
- The operating system and language runtime are maintained and security-patched by the cloud provider, with no maintenance windows required.
- Execution environments are isolated from one another using hardware-backed virtualisation.
- Each customer runs in their own dedicated compute, storage and gateway stack, so one tenant's workload can never read another tenant's data.
- Compute scales automatically with demand, so a spike in load is handled rather than becoming an outage.
7. Encryption at Rest and Certified Data Centres
Everything Punch-in stores, from timesheets to biometric templates, is encrypted at rest and held in UK data centres operated by a leading cloud provider, so your data stays within the United Kingdom.
Built-in Safeguards
- Databases and file storage are encrypted at rest using AES-256, with keys managed by a dedicated key management service.
- Automated backups are taken daily and stored encrypted, separately from the live file system, so data can be restored after accidental deletion or corruption.
- The underlying data centres are independently audited against ISO 27001, SOC 1/2/3 and Cyber Essentials Plus, with 24/7 physical access controls.
- TLS certificates are issued and renewed automatically by the platform, so encryption in transit never lapses.