Security

Security

How we handle payments, customer records and internal access - described at the level of detail a reviewer needs, without publishing anything that would weaken it.

Payment data

Card details are entered on a hosted checkout operated by our payment provider. IveVex does not receive, process or store full card numbers, CVV codes or bank credentials, and our systems are never in the path of that data. We receive a payment identifier, a status, an amount and a currency. Chargebacks, disputes and refunds are executed through the provider.

Customer records

In transit
All traffic is served over HTTPS with modern TLS. There is no unencrypted endpoint.
At rest
Records are held in a managed database with encryption at rest, automated backups and point-in-time recovery.
Minimisation
We collect a name and an email for the certificate, and the payment metadata we are required to keep. Nothing else.

Access control

Administrative access is limited to named studio staff, authenticated individually, with roles stored separately from user profiles and enforced at the database level through row-level security. Every privileged read of customer data goes through an authenticated, role-checked path. Shared logins are not used.

Availability and integrity

Ownership registration is idempotent: a payment confirmation that arrives twice cannot produce two records or two certificates. If a provider confirmation is delayed, the system re-checks the payment status directly with the provider rather than assuming an outcome. Current service state is published on our status page.

Reporting a vulnerability

Report suspected vulnerabilities to hi@ivevex.com with the subject line "Security". We acknowledge within two business days and will keep you informed until the issue is resolved. Please do not test against live customer records, do not attempt denial of service, and give us reasonable time to remediate before publishing.

What we do not claim

We do not currently hold ISO 27001, SOC 2 or PCI DSS certification of our own, and we will not imply otherwise. Card-data compliance sits with our payment provider, which is certified for that purpose. Any certification IveVex obtains will be published here with its scope and date.