Skip to content

Trust

Security

Built on one source of truth: the server decides, the record is permanent, and nobody gets the money desks by accident.

What the platform guarantees

  • Server-verified

    Every bid is checked on the server before it counts. Screens display the outcome — they don't decide it.

  • Immutable ledger

    The auction and the money are an append-only record. Nothing is edited after the fact; corrections are new entries that explain themselves.

  • Recovers itself

    The room's state lives on the server as a snapshot. A dropped phone reconnects to exactly where things are — nothing missed.

  • Access is deliberate, not default

    Money authority is granted, not inherited from a role — owning an organization doesn't hand you the settlement or finance desks. Every grant is auditable.

Under the hood

  • Sign-in codes are short-livedA code lasts five minutes and allows five tries. A number can be sent at most five codes an hour.
  • Codes are never stored as digitsWhat we keep is a keyed digest tied to the code's purpose — a copy of the database cannot turn it back into a code.
  • Sessions you can see and endOnly a hash of each session token is stored, a new token is issued at every sign-in, and every signed-in device is listed on your account with a sign-out.
  • Cookies scripts cannot readSession cookies are HTTP-only and secure-only, so a script on a page cannot lift them.
  • A content policy on every pageEach response carries a Content-Security-Policy with a fresh nonce, so only the scripts we served can run.
  • Your number stays privatePublic player and team pages never show a mobile number or email address.

No passwords to leak

Sign-in is a one-time code to your email or mobile number, or a passkey on your device. There is no password stored anywhere to steal.

Found a problem?

Tell us privately at support@desiauction.in. For anything about your personal data, write to privacy@desiauction.in.

Read the privacy policy

Security · DesiAuction