Security
Boring, on purpose.
The short version: the most sensitive thing in the system, your customers' card details, is handled entirely by Stripe, and everything else is encrypted, backed up and access-controlled.
Card details never touch our servers
Payments are processed by Stripe, a certified PCI DSS Level 1 provider. Card numbers go from your customer's browser to Stripe directly. Schedvia has no way to see or store them.
Your money does not pass through us
Charges settle in your own Stripe account. Stripe deducts Schedvia's fee from the payment itself and passes it to us — Schedvia can never hold your revenue.
Encrypted in transit
Every page and every API call is served over HTTPS. Plain HTTP is redirected.
Backed up daily
The database is backed up every day, and again automatically before every deployment, with restores rehearsed as part of our deploy process.
Hosted in Australia
The application and database run in an Australian data centre.
Passwords hashed, never stored
Account passwords are stored as bcrypt hashes. Staff sign in with their own accounts, separate from the owner's.
Bots kept out
Signup and public forms are protected by challenge, honeypot and timing checks.
Found something?
If you believe you have found a security issue, tell us through the contact page and put "security" in the message. A person reads every report, usually within one business day.