Security & Policies

Data Protection

All requests are validated server-side and stored in protected storage with safe defaults.

Log Privacy

Sensitive data in logs is redacted. IP addresses are stored only as hash in audit records.

Payment Integration

Backend includes dedicated payment-intent endpoint and env-based keys for provider integration.