Encrypted. Isolated. Protected.
For us, security is a daily practice, not a marketing slogan. We encrypt data in transit and at rest, leave payments to PCI-compliant providers, and keep every store isolated on our multi-tenant platform. And we never claim a certification we don't hold.
Security posture
In practice today
Encrypted in transit
All traffic over HTTPS/TLS
Encrypted at rest
Sensitive data encrypted in storage
PCI-compliant payments
Card data never touches our servers
Tenant isolation
Every store logically separated
Tenant isolation
Every store separated
Encryption everywhere
In transit and at rest, by default.
We don't hold card data
PCI-compliant providers handle payments.
Stores stay isolated
Data isolation on a multi-tenant platform.
KVKK & GDPR aligned
Practices aligned with data-protection principles.
FaStart's security practices are in effect today: traffic is encrypted with HTTPS/TLS, sensitive data is encrypted at rest, payments run through PCI-compliant providers so card data never touches our servers, and each store is separated by tenant isolation. Formal certifications like ISO 27001 or SOC 2 are on our roadmap, not claimed. For responsible disclosure, see our trust center.
How we handle security
Most of the below are in effect today; a few items, like formal certifications, are on our roadmap. We label each one honestly.
Data protection aligned with KVKK and GDPR
We align our data-handling practices with KVKK and GDPR principles. The privacy notice, cookie policy, and data-rights channel are published today.
Encryption in transit (HTTPS/TLS)
All traffic between the browser and our servers is encrypted with HTTPS/TLS; data never travels the network in clear text.
Encryption at rest
Sensitive data is encrypted where it's stored; disk-level protection is on by default.
PCI-compliant payment security
Payments run through PCI-compliant providers. Card data stays in their secure infrastructure and never touches our servers.
Role-based access controls
Decide who on your team can see what with roles; give each user only the access they need.
Tenant isolation
On our multi-tenant platform, each store's data is logically separated; one store cannot reach another store's data.
Audited infrastructure and monitoring
Expanding independent audits and continuous security monitoring is on our roadmap; we'll share it plainly as it matures.
Formal certifications (ISO 27001 / SOC 2)
Formal certifications like ISO 27001 and SOC 2 are in our plan. We don't hold them yet, and we won't claim them until we do.
If you find a vulnerability
This page focuses on our security practices and complements our trust center. It links there for responsible disclosure and to the policy center for the full legal detail.
Responsible disclosure
Found a vulnerability or suspicious behavior? We welcome good-faith reports from researchers. Reach us through our trust center and include enough reproduction detail for triage; we'll review and respond.
Policy center
The KVKK privacy notice, cookie policy, terms of use, and all merchant-facing legal documents live in one place, so data-protection detail stays out of marketing copy.
Found a flaw? Report it safely
Our trust center is the front door; here we spell out how a report is handled, what's in scope, and the promise we make to good-faith researchers.
In scope
- FaStart web apps and their subdomains (fastart.co, myfastart.co)
- Vulnerabilities in the dashboard, storefront, and checkout flow
- Authentication, authorization, and tenant-isolation issues
- Sensitive-data exposure or unauthorized access
Out of scope
- Accessing real customer data, deleting data, or attempts to disrupt service
- Social engineering, phishing, and physical attacks
- Volume-based testing (DoS/DDoS) and automated brute-force attempts
- Flaws in third-party services we don't operate
How to report
We don't have a separate security inbox yet; our team handles reports directly.
- 01
Gather the details
Note the affected URL, step-by-step reproduction, and the potential impact.
- 02
Send it to us
Reach us through the trust center, or email contact@fastart.co marked 'security'.
- 03
Let's resolve it
We review, keep you informed, and stay in touch until a fix ships.
Good-faith safe harbor
For good-faith research within this scope, kept confidential, we won't pursue legal action against you. Don't harm real data, protect privacy, and don't share the finding with others until we've fixed it; we'll handle the rest together.
What to expect
We aim to acknowledge every valid good-faith report and to have a real person respond. As an early-stage team we don't commit to a strict timeframe, but we share the process openly. With your permission, we're glad to credit your help once a fix is out.
Paid bounty program (roadmap)
RoadmapA formal, paid vulnerability-reward program is in our plan. We don't offer monetary rewards yet and commit to no payout figures; when the program is ready, we'll publish its scope and rewards here plainly.
Low
Reward range to be defined
Medium
Reward range to be defined
High
Reward range to be defined
Critical
Reward range to be defined
Trust isn't claimed. It's earned.
We label what's live as live and what's planned as roadmap. We describe security with our practices, not with badges we don't hold.
Frequently asked questions
Is my data encrypted?
Yes. We encrypt traffic in transit with HTTPS/TLS and encrypt sensitive data at rest. Encryption is the default behavior, not a setting you switch on later.
Does FaStart store my customers' card details?
No. Payments are processed through PCI-compliant payment providers; raw card data stays in their secure infrastructure and never touches our servers.
Do you hold ISO 27001 or SOC 2?
Not yet. These certifications are on our roadmap and we'll announce them clearly once we hold them. We never claim a certification we don't have.
Can one store see another store's data?
No. On our multi-tenant platform, each store's data is logically separated (tenant isolation); one store cannot reach another's data.
Can everyone on my team see everything?
With role-based access controls, you decide who can see what; you give each person only the access they need.
I found a vulnerability, how do I report it?
Reach us through our trust center and include enough reproduction detail for triage. We take responsible disclosure seriously and welcome good-faith reports from researchers.
Around security
Security connects to the rest of your store.
Start on a platform that takes security seriously.
Encryption, PCI-compliant payments, and tenant isolation are in effect today. Try the demo, then get started.