Security

Last updated: October 7, 2026

Infrastructure

  • Hosted in the United States behind TLS (HTTPS everywhere, HSTS).
  • Database not exposed to the internet; nightly backups.
  • Isolated application containers; production changes are tested on a throwaway copy before they go live.

Application

  • Passwords hashed with a modern slow hash; sessions signed and revocable.
  • Role-based permissions for every facility user; platform-staff access is audited.
  • Payment card data never touches our servers — cards are tokenized in the browser by the facility's payment gateway (Accept.js).
  • Gateway, SMTP and SMS credentials encrypted at rest (AES-256-GCM).
  • ID documents encrypted, every view logged, and auto-deleted on the facility's schedule.
  • Spam and abuse protection on public forms; rate limiting on logins.

People and process

Least-privilege access, audit logs for sensitive actions, and dependency updates.

Compliance scope

  • PCI DSS: card entry uses Authorize.net Accept.js, so card data goes straight to the processor. Facilities qualify for the smallest self-assessment (SAQ A) for online payments.
  • Access controls: staff access is role-based and least-privilege, with an audit log of sensitive actions.

Report a vulnerability

Email security@storagereservations.com. Please give us reasonable time to fix issues before disclosure; we don't pursue good-faith research.