Security

Boring, on purpose.

The short version: the most sensitive thing in the system, your customers' card details, is handled entirely by Stripe, and everything else is encrypted, backed up and access-controlled.

Card details never touch our servers

Payments are processed by Stripe, a certified PCI DSS Level 1 provider. Card numbers go from your customer's browser to Stripe directly. Schedvia has no way to see or store them.

Your money does not pass through us

Charges settle in your own Stripe account. Stripe deducts Schedvia's fee from the payment itself and passes it to us — Schedvia can never hold your revenue.

Encrypted in transit

Every page and every API call is served over HTTPS. Plain HTTP is redirected.

Backed up daily

The database is backed up every day, and again automatically before every deployment, with restores rehearsed as part of our deploy process.

Hosted in Australia

The application and database run in an Australian data centre.

Passwords hashed, never stored

Account passwords are stored as bcrypt hashes. Staff sign in with their own accounts, separate from the owner's.

Bots kept out

Signup and public forms are protected by challenge, honeypot and timing checks.

Found something?

If you believe you have found a security issue, tell us through the contact page and put "security" in the message. A person reads every report, usually within one business day.