Trust
Security at Barqish
How we protect your account and your data, and how to tell us about a weakness.
How your account is protected
- The whole site runs on HTTPS with HSTS, so browsers never connect without encryption.
- Passwords are stored only as salted one-way hashes. We cannot see them.
- New passwords are checked against known data breaches using the Have I Been Pwned range service. Only the first 5 characters of a hash of the password leave our server; the password itself never does.
- New sign-ins from a device we have not seen before trigger an email with a one-tap link that signs out every device.
- Pro members can turn on two-step sign-in with an authenticator app (Google Authenticator, Microsoft Authenticator, Authy or similar), with one-time recovery codes.
- New accounts confirm their email with a 6-digit code before payments or email alerts.
- Sign-in, sign-up, password reset and code checks are rate-limited.
What we never hold
- Card numbers, bank passwords, exchange passwords or API keys, or wallet private keys. Barqish is not a broker and never holds your money.
- We will never ask you for a password, a confirmation code or a recovery code by email, phone or WhatsApp.
On the server
- Security headers on every page: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy.
- A Content Security Policy runs in report-only mode while we confirm it blocks nothing members need; it will then be enforced.
- Daily on-site backups and weekly off-site backups.
- File editing in the WordPress dashboard is switched off.
Report a security problem
Email [email protected] with the subject "Security". Please include the page or address, what you found and the steps to reproduce it.
Our machine-readable contact file is at /.well-known/security.txt.
Our promise to researchers
- We reply within 3 working days and keep you updated until the issue is fixed.
- If you act in good faith and follow these rules, we will not take legal action against you.
- With your permission, we will thank you by name on this page.
Please do not
- Access, change or delete other members' data. Use your own test account.
- Run denial-of-service tests, automated scanning at high volume, spam or social engineering of our team or members.
- Test payment providers, Cloudflare or other third-party services; report issues there to their owners.
- Share the issue publicly before we have fixed it.
Thank you
No reports yet. Be the first to help us make Barqish safer.
Last updated 2 October 2026. See also our Privacy Policy and accessibility statement.