Secure transport
Production uses HTTPS. The app blocks cleartext traffic and limits internal navigation to approved Total Value hosts.
Authentication
Firebase verifies identity. Android tokens travel in the HTTPS request body, and production sessions use protected cookies.
Least access
The WebView cannot access local files or content, blocks mixed content, and opens external links in the system browser.
Operational protection
Controls include input validation, request limiting, environment separation, data minimization, access control, security logs, and dependency maintenance. These pages use CSP, framing protection, restricted permissions, and MIME-sniffing protection.
Protect your account
- Use a unique password and protect your Google account.
- Never email passwords, tokens, or full payment data.
- Sign out of shared devices and keep software updated.
- Verify the address uses totalvalue.com.br over HTTPS.
Report a vulnerability
Email steps, impact, and a concise description to contato@totalvalue.com.br. Do not access third-party data, disrupt the service, or disclose the issue before reasonable investigation. See security.txt.
Limits
No system eliminates all risk. We investigate significant events and take containment, remediation, and legally required notification measures.