Trust
Security
Built on one source of truth: the server decides, the record is permanent, and nobody gets the money desks by accident.
What the platform guarantees
Server-verified
Every bid is checked on the server before it counts. Screens display the outcome — they don't decide it.
Immutable ledger
The auction and the money are an append-only record. Nothing is edited after the fact; corrections are new entries that explain themselves.
Recovers itself
The room's state lives on the server as a snapshot. A dropped phone reconnects to exactly where things are — nothing missed.
Access is deliberate, not default
Money authority is granted, not inherited from a role — owning an organization doesn't hand you the settlement or finance desks. Every grant is auditable.
Under the hood
- Sign-in codes are short-livedA code lasts five minutes and allows five tries. A number can be sent at most five codes an hour.
- Codes are never stored as digitsWhat we keep is a keyed digest tied to the code's purpose — a copy of the database cannot turn it back into a code.
- Sessions you can see and endOnly a hash of each session token is stored, a new token is issued at every sign-in, and every signed-in device is listed on your account with a sign-out.
- Cookies scripts cannot readSession cookies are HTTP-only and secure-only, so a script on a page cannot lift them.
- A content policy on every pageEach response carries a Content-Security-Policy with a fresh nonce, so only the scripts we served can run.
- Your number stays privatePublic player and team pages never show a mobile number or email address.
No passwords to leak
Sign-in is a one-time code to your email or mobile number, or a passkey on your device. There is no password stored anywhere to steal.
Found a problem?
Tell us privately at support@desiauction.in. For anything about your personal data, write to privacy@desiauction.in.