Skip to main content

Introducing Loss Radar: see which shift cost you money.Learn more

Security · last reviewed May 28, 2026

AES-256 at rest. TLS 1.3 in transit. Audit log immutable.

How we protect your data, who has access, and how to report a vulnerability. Refer your security team here before diligence.

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

Immutable

Audit log retention

US-only

Data residency

01 · Data protection

How operator data is stored, encrypted, and recovered.

Encryption at rest

All customer data is encrypted at rest using AES-256.

  • Database storage encrypted via AWS RDS-managed keys
  • File storage encrypted via S3 server-side encryption (SSE-S3)
  • Backup snapshots inherit the same encryption posture
  • Key rotation runs quarterly on AWS-managed key material
Encryption in transit

All traffic uses TLS 1.3, with strict HSTS preload.

  • HTTP requests on stationpro.ai redirect to HTTPS
  • HSTS max-age set to 63072000 seconds (2 years) with includeSubDomains and preload
  • TLS 1.0 / 1.1 explicitly disabled
  • mTLS used between internal services for production traffic
Data residency

Operator data is stored in the United States — AWS us-east-1 (primary), us-west-2 (failover).

  • No production data leaves the United States
  • EU / international hosting available on request for chain-tier customers
Backups and retention

Continuous binlog backups + daily snapshots, 30-day rolling retention.

  • Point-in-time recovery to any 5-minute window in the last 30 days
  • Long-term archival snapshots retained for 7 years for compliance
  • Tested restore drills run quarterly

02 · Access controls

Who can see what, and how that's enforced.

Role-based access

Owner, regional manager, store manager, and clerk roles each carry explicit, audited permission scopes.

  • Per-store data isolation enforced at the database row level
  • Clerks see only their store and their shift; managers see their stores
  • Owners see the full portfolio
  • Every permission change is logged to the audit trail
Single sign-on

SAML 2.0 SSO available on the Portfolio plan — Google and Microsoft SSO available on every plan.

  • Native SAML 2.0 with any IdP (Okta, Azure AD, Google Workspace, OneLogin)
  • SCIM 2.0 user provisioning for enterprise customers
  • Session timeout configurable per tenant
Multi-factor authentication

MFA via TOTP (Google Authenticator, 1Password, Authy) and WebAuthn (hardware keys).

  • Optional on Starter / Growth plans
  • Required by default on Portfolio
  • Enforceable per tenant via admin policy
Audit log

Every action — login, EOD submit, void, refund, invoice edit, permission change — is written to an immutable, queryable audit log.

  • Per-record before/after values for every change
  • IP, user, timestamp, action type captured on every event
  • Append-only storage; admin role cannot delete entries
  • CSV export for outside auditors
  • 7-year retention by default; per-tenant overrides available

03 · Infrastructure

Where and how StationPro runs in production.

Hosting

AWS us-east-1 (primary), us-west-2 (failover). Multi-AZ database with automated failover.

  • Application tier runs on Vercel (edge + regional functions)
  • Database on AWS RDS with multi-AZ replication
  • File storage on S3 with cross-region replication
  • CDN: Vercel edge with built-in DDoS protection
Network security

Private VPC, no public database access, WAF in front of every customer-facing endpoint.

  • Production databases are not publicly reachable
  • All internal traffic flows over private VPC peering
  • AWS WAF rules block common OWASP Top-10 patterns and rate-limit suspicious traffic
Content Security Policy

Strict CSP with frame-ancestors none, object-src none, and per-host script allowlist.

  • No third-party script can execute outside the allowlist (Plaid, Calendly)
  • CSP violations are reported and reviewed weekly
  • Permissions-Policy explicitly disables camera, microphone, geolocation, payment

04 · Compliance

Audits, frameworks, and regulatory posture.

PCI DSS scope

StationPro is not in the cardholder-data path — we read transaction-level tender summaries from the POS, not card numbers.

  • Customers stay in SAQ-B / SAQ-C compliance levels
  • No card data ever stored in StationPro databases
  • Payment processing handled by the customer's existing POS / processor
Sub-processors

A complete list of every vendor that processes operator data on our behalf is maintained and updated within 30 days of any change.

  • AWS — hosting and storage
  • Vercel — application delivery + edge runtime
  • Supabase — managed Postgres (for tenants opting into managed DB)
  • Plaid — banking account aggregation
  • Anthropic — AI Assistant LLM (operator data is sent only on explicit user query)
  • Web3Forms — website form delivery (demo and contact requests)
GDPR and CCPA

Operators have full export and deletion rights via the dashboard. Sub-processor list and DPA available on request.

  • Right to access: full CSV export from the dashboard
  • Right to deletion: hard delete with 30-day read-only grace period
  • Right to portability: structured exports in JSON or CSV
  • CCPA "Do Not Sell" honored automatically (we do not sell)

05 · Disclosure

Responsible disclosure.

Found a vulnerability? Email stationproai@gmail.com with “Security disclosure” in the subject. We respond within one business day.

  • We commit to a fix or remediation plan within 30 days of triage for confirmed vulnerabilities
  • No legal action against good-faith security researchers
  • Public credit (or anonymous, at your preference) on the security advisories page once the fix ships
  • No paid bug bounty yet — recognition only. Adding HackerOne / Bugcrowd is on the roadmap.

PGP key for sensitive reports available on request via the same address.

Available on request.

For active prospects and customers, the following documents are available under NDA:

  • Penetration-test summary (most recent)
  • Sub-processor list with role + scope
  • Data Processing Agreement (DPA)
  • Business Associate Agreement (BAA)
  • Incident response runbook
  • Vendor-due-diligence questionnaire response

Need to evaluate against your security checklist?

A 30-minute walk-through with a founder. Bring your IT/security stakeholders — we'll answer everything in real time.