Your data is safe
Security you can count on
Stampvio is built with enterprise-grade security practices so your business and customer data stays protected.
How we protect you
Security pillars
Data Encryption
- All traffic encrypted in transit with HTTPS
- Sensitive data encrypted at rest
- Secure hosting on modern cloud infrastructure
Authentication
- JWT access tokens in httpOnly cookies
- bcrypt password hashing for business accounts
- OTP email verification and Google OAuth for customers
Access Control
- Role-based access: Admin, Owner, Staff, Customer
- Plan-based feature gating via CASL
- Least-privilege defaults for staff invites
Rate Limiting
- OTP requests capped to prevent abuse
- Stamp cooldown enforced server-side
- API throttling across public endpoints
Payments
- Checkout handled by Lemon Squeezy
- Stampvio never stores card details
- Webhook signature verification on subscription events
Uptime
- 99.5% uptime target for the production API
- Frontend hosted on Vercel
- Backend hosted on Railway with health monitoring
Trust signals
Built on proven practices
HTTPS EnforcedLemon Squeezy Paymentsbcrypt HashingJWT AuthGoogle OAuth