1. Security model
Security is planned across identity, application, infrastructure, integration, and operational layers. We use risk-based controls and review them as the service grows. This page describes our approach and is not a certification or guarantee.
2. Data protection
- TLS protects data in transit and encryption protects stored service data.
- Prepacity does not need payment-card data to plan capacity.
- Sensitive values are redacted from logs and secrets are stored outside source control.
- Retention, export, tenant deletion, and customer-erasure workflows support responsible data lifecycle management.
- Backups, recovery procedures, and service monitoring are designed to support resilience.
3. Identity and access
- Server-side authentication and current password-hashing practices.
- Role-based access controls and least-privilege administrative access.
- OAuth for connected platforms where supported and rotatable connector secrets.
- Audit logs for important user and operator actions.
- Optional advanced identity features may be available on eligible plans.
4. Application and integration security
- Rate limiting, CSRF protection, content security policy, and defensive input validation.
- Signed outbound webhooks and verification of supported inbound platform requests.
- Atomic booking controls that help prevent two shoppers from acquiring the final available capacity.
- Dependency, container, and release scanning within the development lifecycle.
- Versioned APIs and scoped integrations designed to limit unnecessary access.
5. Operational security
We monitor service and connector health, maintain incident response procedures, and investigate suspicious activity. Access to production systems and customer information is limited to authorised personnel with a legitimate need.
Security depends on shared responsibility. Merchants should use unique credentials, assign the narrowest practical roles, promptly remove former users, keep connected platforms secure, and report unusual activity.
6. Reporting vulnerabilities
If you believe you found a vulnerability, email security@prepacity.com with enough detail to reproduce it. Please avoid privacy violations, disruption, social engineering, destructive testing, and accessing data that is not yours. We will acknowledge good-faith reports and coordinate next steps.