Security · last reviewed May 28, 2026
AES-256 at rest. TLS 1.3 in transit. Audit log immutable.
How we protect your data, who has access, and how to report a vulnerability. Refer your security team here before diligence.
Encryption at rest
Encryption in transit
Audit log retention
Data residency
01 · Data protection
How operator data is stored, encrypted, and recovered.
- Encryption at rest
All customer data is encrypted at rest using AES-256.
- Database storage encrypted via AWS RDS-managed keys
- File storage encrypted via S3 server-side encryption (SSE-S3)
- Backup snapshots inherit the same encryption posture
- Key rotation runs quarterly on AWS-managed key material
- Encryption in transit
All traffic uses TLS 1.3, with strict HSTS preload.
- HTTP requests on stationpro.ai redirect to HTTPS
- HSTS max-age set to 63072000 seconds (2 years) with includeSubDomains and preload
- TLS 1.0 / 1.1 explicitly disabled
- mTLS used between internal services for production traffic
- Data residency
Operator data is stored in the United States — AWS us-east-1 (primary), us-west-2 (failover).
- No production data leaves the United States
- EU / international hosting available on request for chain-tier customers
- Backups and retention
Continuous binlog backups + daily snapshots, 30-day rolling retention.
- Point-in-time recovery to any 5-minute window in the last 30 days
- Long-term archival snapshots retained for 7 years for compliance
- Tested restore drills run quarterly
02 · Access controls
Who can see what, and how that's enforced.
- Role-based access
Owner, regional manager, store manager, and clerk roles each carry explicit, audited permission scopes.
- Per-store data isolation enforced at the database row level
- Clerks see only their store and their shift; managers see their stores
- Owners see the full portfolio
- Every permission change is logged to the audit trail
- Single sign-on
SAML 2.0 SSO available on the Portfolio plan — Google and Microsoft SSO available on every plan.
- Native SAML 2.0 with any IdP (Okta, Azure AD, Google Workspace, OneLogin)
- SCIM 2.0 user provisioning for enterprise customers
- Session timeout configurable per tenant
- Multi-factor authentication
MFA via TOTP (Google Authenticator, 1Password, Authy) and WebAuthn (hardware keys).
- Optional on Starter / Growth plans
- Required by default on Portfolio
- Enforceable per tenant via admin policy
- Audit log
Every action — login, EOD submit, void, refund, invoice edit, permission change — is written to an immutable, queryable audit log.
- Per-record before/after values for every change
- IP, user, timestamp, action type captured on every event
- Append-only storage; admin role cannot delete entries
- CSV export for outside auditors
- 7-year retention by default; per-tenant overrides available
03 · Infrastructure
Where and how StationPro runs in production.
- Hosting
AWS us-east-1 (primary), us-west-2 (failover). Multi-AZ database with automated failover.
- Application tier runs on Vercel (edge + regional functions)
- Database on AWS RDS with multi-AZ replication
- File storage on S3 with cross-region replication
- CDN: Vercel edge with built-in DDoS protection
- Network security
Private VPC, no public database access, WAF in front of every customer-facing endpoint.
- Production databases are not publicly reachable
- All internal traffic flows over private VPC peering
- AWS WAF rules block common OWASP Top-10 patterns and rate-limit suspicious traffic
- Content Security Policy
Strict CSP with frame-ancestors none, object-src none, and per-host script allowlist.
- No third-party script can execute outside the allowlist (Plaid, Calendly)
- CSP violations are reported and reviewed weekly
- Permissions-Policy explicitly disables camera, microphone, geolocation, payment
04 · Compliance
Audits, frameworks, and regulatory posture.
- PCI DSS scope
StationPro is not in the cardholder-data path — we read transaction-level tender summaries from the POS, not card numbers.
- Customers stay in SAQ-B / SAQ-C compliance levels
- No card data ever stored in StationPro databases
- Payment processing handled by the customer's existing POS / processor
- Sub-processors
A complete list of every vendor that processes operator data on our behalf is maintained and updated within 30 days of any change.
- AWS — hosting and storage
- Vercel — application delivery + edge runtime
- Supabase — managed Postgres (for tenants opting into managed DB)
- Plaid — banking account aggregation
- Anthropic — AI Assistant LLM (operator data is sent only on explicit user query)
- Web3Forms — website form delivery (demo and contact requests)
- GDPR and CCPA
Operators have full export and deletion rights via the dashboard. Sub-processor list and DPA available on request.
- Right to access: full CSV export from the dashboard
- Right to deletion: hard delete with 30-day read-only grace period
- Right to portability: structured exports in JSON or CSV
- CCPA "Do Not Sell" honored automatically (we do not sell)
05 · Disclosure
Responsible disclosure.
Found a vulnerability? Email stationproai@gmail.com with “Security disclosure” in the subject. We respond within one business day.
- We commit to a fix or remediation plan within 30 days of triage for confirmed vulnerabilities
- No legal action against good-faith security researchers
- Public credit (or anonymous, at your preference) on the security advisories page once the fix ships
- No paid bug bounty yet — recognition only. Adding HackerOne / Bugcrowd is on the roadmap.
PGP key for sensitive reports available on request via the same address.
Available on request.
For active prospects and customers, the following documents are available under NDA:
- Penetration-test summary (most recent)
- Sub-processor list with role + scope
- Data Processing Agreement (DPA)
- Business Associate Agreement (BAA)
- Incident response runbook
- Vendor-due-diligence questionnaire response
Need to evaluate against your security checklist?
A 30-minute walk-through with a founder. Bring your IT/security stakeholders — we'll answer everything in real time.
