HTTPS and HSTS
Browser and API traffic is forced onto secure transport.
Security
Review signed access, narrow data fields and fail-closed decisions now. The assurance contract binds every assessment to the exact release candidate.
Browser and API traffic is forced onto secure transport.
A guessed order number does not open a private record.
HMAC, store authority and delivery identity are checked before an event is accepted.
Inactive merchants lose every session. Read-only users can inspect but cannot change orders, evidence, integrations or billing.
Authenticated writes and one-time-link consumption are rejected when the request origin cannot be verified.
Forwarded client and protocol headers are accepted only from configured proxy ranges; blanket trust ranges are rejected.
A distributed Redis-backed limiter is active; public events, authentication and Item Check use bounded quotas.
The application runs under a dedicated non-root user.
Persistent backups are encrypted. The institution pack binds off-site copy and timed clean-room recovery evidence to the deployment under review.
Privileged routes require an admin credential and append an access event.
Assessor identity, findings and signed retest records attach to the exact release candidate reviewed.
Responsible disclosure
Include the affected path, impact, reproduction steps and a safe contact. Do not access customer records or degrade the service.
Submit a security report →