How we protect the platform
- Row level access rules so each account can reach only its own data.
- Balances and payments can only be changed by validated server side processes.
- Traffic is encrypted in transit, and card details are handled by Stripe, never by us.
- Administrative access is limited to what is needed to operate the service.
- Sensitive actions in the admin console are recorded in an audit log.
These are the controls we operate today. They are not a certification, and no service can promise it will never be breached.
