Layered protection

Security at Total Value

How we protect accounts and data, and how to report a vulnerability.

Secure transport

Production uses HTTPS. The app blocks cleartext traffic and limits internal navigation to approved Total Value hosts.

Authentication

Firebase verifies identity. Android tokens travel in the HTTPS request body, and production sessions use protected cookies.

Least access

The WebView cannot access local files or content, blocks mixed content, and opens external links in the system browser.

Operational protection

Controls include input validation, request limiting, environment separation, data minimization, access control, security logs, and dependency maintenance. These pages use CSP, framing protection, restricted permissions, and MIME-sniffing protection.

Protect your account

Report a vulnerability

Email steps, impact, and a concise description to contato@totalvalue.com.br. Do not access third-party data, disrupt the service, or disclose the issue before reasonable investigation. See security.txt.

Limits

No system eliminates all risk. We investigate significant events and take containment, remediation, and legally required notification measures.