Skip to main content
SecurityIn practice today

Encrypted. Isolated. Protected.

For us, security is a daily practice, not a marketing slogan. We encrypt data in transit and at rest, leave payments to PCI-compliant providers, and keep every store isolated on our multi-tenant platform. And we never claim a certification we don't hold.

Security posture

In practice today

Live

Encrypted in transit

All traffic over HTTPS/TLS

Encrypted at rest

Sensitive data encrypted in storage

PCI-compliant payments

Card data never touches our servers

Tenant isolation

Every store logically separated

Tenant isolation

Every store separated

Encryption everywhere

In transit and at rest, by default.

We don't hold card data

PCI-compliant providers handle payments.

Stores stay isolated

Data isolation on a multi-tenant platform.

KVKK & GDPR aligned

Practices aligned with data-protection principles.

FaStart's security practices are in effect today: traffic is encrypted with HTTPS/TLS, sensitive data is encrypted at rest, payments run through PCI-compliant providers so card data never touches our servers, and each store is separated by tenant isolation. Formal certifications like ISO 27001 or SOC 2 are on our roadmap, not claimed. For responsible disclosure, see our trust center.

Security practices

How we handle security

Most of the below are in effect today; a few items, like formal certifications, are on our roadmap. We label each one honestly.

Live

Data protection aligned with KVKK and GDPR

We align our data-handling practices with KVKK and GDPR principles. The privacy notice, cookie policy, and data-rights channel are published today.

Live

Encryption in transit (HTTPS/TLS)

All traffic between the browser and our servers is encrypted with HTTPS/TLS; data never travels the network in clear text.

Live

Encryption at rest

Sensitive data is encrypted where it's stored; disk-level protection is on by default.

Live

PCI-compliant payment security

Payments run through PCI-compliant providers. Card data stays in their secure infrastructure and never touches our servers.

Configurable

Role-based access controls

Decide who on your team can see what with roles; give each user only the access they need.

Live

Tenant isolation

On our multi-tenant platform, each store's data is logically separated; one store cannot reach another store's data.

Roadmap

Audited infrastructure and monitoring

Expanding independent audits and continuous security monitoring is on our roadmap; we'll share it plainly as it matures.

Roadmap

Formal certifications (ISO 27001 / SOC 2)

Formal certifications like ISO 27001 and SOC 2 are in our plan. We don't hold them yet, and we won't claim them until we do.

If you find a vulnerability

This page focuses on our security practices and complements our trust center. It links there for responsible disclosure and to the policy center for the full legal detail.

Responsible disclosure

Found a vulnerability or suspicious behavior? We welcome good-faith reports from researchers. Reach us through our trust center and include enough reproduction detail for triage; we'll review and respond.

Policy center

The KVKK privacy notice, cookie policy, terms of use, and all merchant-facing legal documents live in one place, so data-protection detail stays out of marketing copy.

Responsible disclosureLive

Found a flaw? Report it safely

Our trust center is the front door; here we spell out how a report is handled, what's in scope, and the promise we make to good-faith researchers.

In scope

  • FaStart web apps and their subdomains (fastart.co, myfastart.co)
  • Vulnerabilities in the dashboard, storefront, and checkout flow
  • Authentication, authorization, and tenant-isolation issues
  • Sensitive-data exposure or unauthorized access

Out of scope

  • Accessing real customer data, deleting data, or attempts to disrupt service
  • Social engineering, phishing, and physical attacks
  • Volume-based testing (DoS/DDoS) and automated brute-force attempts
  • Flaws in third-party services we don't operate

How to report

We don't have a separate security inbox yet; our team handles reports directly.

  1. 01
    Gather the details

    Note the affected URL, step-by-step reproduction, and the potential impact.

  2. 02
    Send it to us

    Reach us through the trust center, or email contact@fastart.co marked 'security'.

  3. 03
    Let's resolve it

    We review, keep you informed, and stay in touch until a fix ships.

Good-faith safe harbor

For good-faith research within this scope, kept confidential, we won't pursue legal action against you. Don't harm real data, protect privacy, and don't share the finding with others until we've fixed it; we'll handle the rest together.

What to expect

We aim to acknowledge every valid good-faith report and to have a real person respond. As an early-stage team we don't commit to a strict timeframe, but we share the process openly. With your permission, we're glad to credit your help once a fix is out.

Paid bounty program (roadmap)

Roadmap

A formal, paid vulnerability-reward program is in our plan. We don't offer monetary rewards yet and commit to no payout figures; when the program is ready, we'll publish its scope and rewards here plainly.

Roadmap · Concept

Low

Reward range to be defined

Medium

Reward range to be defined

High

Reward range to be defined

Critical

Reward range to be defined

Concept preview

Trust isn't claimed. It's earned.

We label what's live as live and what's planned as roadmap. We describe security with our practices, not with badges we don't hold.

Frequently asked questions

Is my data encrypted?

Yes. We encrypt traffic in transit with HTTPS/TLS and encrypt sensitive data at rest. Encryption is the default behavior, not a setting you switch on later.

Does FaStart store my customers' card details?

No. Payments are processed through PCI-compliant payment providers; raw card data stays in their secure infrastructure and never touches our servers.

Do you hold ISO 27001 or SOC 2?

Not yet. These certifications are on our roadmap and we'll announce them clearly once we hold them. We never claim a certification we don't have.

Can one store see another store's data?

No. On our multi-tenant platform, each store's data is logically separated (tenant isolation); one store cannot reach another's data.

Can everyone on my team see everything?

With role-based access controls, you decide who can see what; you give each person only the access they need.

I found a vulnerability, how do I report it?

Reach us through our trust center and include enough reproduction detail for triage. We take responsible disclosure seriously and welcome good-faith reports from researchers.

Start on a platform that takes security seriously.

Encryption, PCI-compliant payments, and tenant isolation are in effect today. Try the demo, then get started.