Loading
Loading
Security
What we do today, what's coming next, and where the data lives. Honest, specific, no buzzword bingo.
Every byte you put into SalesThumb is encrypted in flight and at rest.
Shops can't see each other's data. Period.
Strong defaults, role-based controls, and single sign-on with Google.
Boring fundamentals done right.
Modern, audited platform partners do the heavy lifting — the certifications below are the providers' own; SalesThumb's own SOC 2 is not yet started (see Compliance).
What happens when something goes wrong.
Where we are today; we'll publish artifacts as audits land.
SOC 2
Not startedNo third-party audit engagement yet. Planned post-launch — we'll publish real dates once an auditor is engaged, not before.
GDPR (Data Processing Addendum)
AvailableEmail info@roffik.com to receive a signed DPA.
PCI compliance
By designCard data is handled entirely by our payment processor — we never store full card numbers on our servers.
TCPA opt-out
EnforcedSTOP / START keywords are honored automatically; opt-outs persist across channels.
Responsible disclosure is welcomed and credited. Email info@roffik.com with reproduction steps and we'll acknowledge within 24 hours.
Application data lives in a managed Postgres instance on Neon (AWS us-east-1 by default). Files (photos, PDFs, certificates) live on Cloudflare R2 with global edge distribution. Both providers carry SOC 2 Type II attestations.
Direct database access is restricted to a small list of named operators on call for incidents, all of whom have MFA enforced. Routine support happens through impersonation tokens that are scoped, time-bound, and recorded in the per-shop audit log. We don't browse customer data for any reason except a documented support request.
Your data stays exactly where it is for 60 days, accessible via export. After 60 days of cancelled status it's deleted from the live database; backups follow the standard 7-day retention. Email info@roffik.com to request immediate erasure.
No. Card details are tokenized by our payment processor at entry and never reach our servers. We hold a payment-processor customer identifier and the last four digits of the most recent card — that's it.
Email info@roffik.com with a description of the issue and steps to reproduce. We acknowledge within 24 hours and aim to resolve high-severity issues within 7 days. We don't have a paid bug bounty yet but will publicly credit responsible disclosures.