We, Seigisoft, as a Software Development company, we are first compromised with Secure development. That’s why, we decide to employ the following methodologies to ensure basic security.
Methodologies
OWASP Application Security Verification Standard (ASVS)
We are commited to improve our codebase to match the maximum level (L3) gradually.
To do so, we ensure that the code base is automatically tested to make sure these requirements are always respected and manually reviewed.
L1 Requirements
V1.2 Injection Prevention
- 1.2.1 [ ]: Verify that output encoding for an HTTP response, HTML document, or XML document is relevant for the context required, such as encoding the relevant characters for HTML elements, HTML attributes, HTML comments, CSS, or HTTP header fields, to avoid changing the message or document structure.
- 1.2.2 [ ]: Verify that when dynamically building URLs, untrusted data is encoded according to its context (e.g., URL encoding or base64url encoding for query or path parameters). Ensure that only safe URL protocols are permitted (e.g., disallow javascript: or data:).
- 1.2.3 [ ]: Verify that output encoding or escaping is used when dynamically building JavaScript content (including JSON), to avoid changing the message or document structure (to avoid JavaScript and JSON injection)
- 1.2.4 [ ]: Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks.
- 1.2.5 [ ]: Verify that the application protects against OS command injection and that operating system calls use parameterized OS queries or use contextual command line output encoding.
V1.3 Sanitization
- 1.3.1 [ ]: Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well‑known and secure HTML sanitization library or framework feature.
- 1.3.2 [ ]: Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.
V1.5 Safe Deserialization
- 1.5.1 [ ]: Verify that the application configures XML parsers to use a restrictive configuration and that unsafe features such as resolving external entities are disabled to prevent XML eXternal Entity (XXE) attacks.