Security

How we protect accounts, customer records and payments — and how to tell us if you find a problem.

Encryption

Traffic is served over HTTPS, and data is encrypted at rest by our hosting and database providers.

Workspace isolation

Every record belongs to a workspace, and database-level row security keeps one business from reading another's data. Team members only see the modules and records their role allows.

Payments

Card details are handled by Stripe and never touch our servers. Payouts go directly to each business's own connected account.

Access and monitoring

Sensitive actions — invites, role changes, refunds — are written to an audit log. Public forms are rate-limited to reduce abuse.

Reporting a vulnerability

If you believe you have found a security issue, please tell us privately before sharing it publicly. We read every report and will confirm receipt.

Send reports to

support@bizinnabox.net

Email the security team

Please include

  • What you found and why you think it is a problem.
  • The exact steps to reproduce it, including URLs.
  • Any accounts, screenshots or request logs involved.
  • How you would like to be credited, if at all.

Responsible disclosure

We will not pursue action against researchers who report in good faith, act within the guidelines below, and give us reasonable time to fix an issue before disclosing it.

  • Only test against accounts you own. Never access, modify or delete another person's data.
  • Do not run denial-of-service, spam, or high-volume automated scans against the service.
  • Do not use social engineering or physical attacks against our team or providers.
  • Give us a reasonable window to fix the issue before publishing details.

We do not currently run a paid bug bounty programme. Valid reports are still very welcome and we are happy to credit you.

Not a vulnerability?

For account, billing or product problems, use the support form. To report misuse of the platform, see the Acceptable Use Policy.