Where Data Lives
The application and its database run on Railway in the United States (US West region). Uploaded files live in Google Firebase Storage. Both providers encrypt data at rest on their cloud disks and hold recognized security certifications. Every connection to and from the service uses TLS.
Access Control
Accounts sign in with a one-time code sent to a verified phone or email. Access inside a business is role based (owner, manager, team member) and scoped to that business only. Our operations staff reach client data only for support and operations, and every administrative action is written to an audit log. A certified partner sees a client’s data only after the client grants access, which the client can revoke at any time.
Encryption and Secrets
Vendor tokens and card-on-file tokens are encrypted with AES-256-GCM before they are stored. Payment card numbers are entered on PayPlus’s hosted page and never reach our servers, which keeps us within the PCI DSS SAQ A profile.
Application Security
Security headers on every response, request rate limiting, input validation on every endpoint, signature verification on incoming webhooks from Meta and PayPlus, bot protection on public forms, and automated checks that block unsafe database migrations and import cycles before a deploy.
Logging and Monitoring
Administrative actions, authentication failures and security events are logged and kept for at least 24 months. Application errors are monitored with Sentry without personal data. Background jobs are visible in an operations panel with their run history.
Backups and Continuity
The database is a managed cloud service with provider-level redundancy and backups. Our security procedure sets the backup schedule and a restore test, and a staging environment lets us rehearse changes before they reach production.
Incident Response
A written runbook covers detection, containment, assessment, notification to affected clients within 72 hours of confirmation, reporting of serious incidents to the Privacy Protection Authority, and a post-incident review.
Compliance
We operate under the Israeli Privacy Protection Law and the Data Security Regulations at the medium security level: a database definitions document, a security procedure, a permissions register, a vendor register with data-processing undertakings from every subprocessor, staff training before access is granted, and a security audit at least every 24 months. Our AI assistants disclose that they are automated, hand over to a person on request, and never give medical, legal or financial advice.
Reporting a Vulnerability
If you believe you have found a security issue, write to [email protected]. We acknowledge reports within two business days and do not take action against good-faith research.
Need a security questionnaire completed or our vendor register for a procurement review? Write to [email protected].