Your data is safe

Security you can count on

Stampvio is built with enterprise-grade security practices so your business and customer data stays protected.

How we protect you

Security pillars

Data Encryption

  • All traffic encrypted in transit with HTTPS
  • Sensitive data encrypted at rest
  • Secure hosting on modern cloud infrastructure

Authentication

  • JWT access tokens in httpOnly cookies
  • bcrypt password hashing for business accounts
  • OTP email verification and Google OAuth for customers

Access Control

  • Role-based access: Admin, Owner, Staff, Customer
  • Plan-based feature gating via CASL
  • Least-privilege defaults for staff invites

Rate Limiting

  • OTP requests capped to prevent abuse
  • Stamp cooldown enforced server-side
  • API throttling across public endpoints

Payments

  • Checkout handled by Lemon Squeezy
  • Stampvio never stores card details
  • Webhook signature verification on subscription events

Uptime

  • 99.5% uptime target for the production API
  • Frontend hosted on Vercel
  • Backend hosted on Railway with health monitoring
Trust signals

Built on proven practices

HTTPS EnforcedLemon Squeezy Paymentsbcrypt HashingJWT AuthGoogle OAuth

Questions about our security practices?

Contact our team — we are happy to walk through how Stampvio keeps data safe.