Security
Effective October 7, 2026 · Version 2026-10-07.2
How we protect data
- All traffic is encrypted with HTTPS (HSTS on), and sign-in and connection tokens are encrypted at rest.
- Each business’s data is separated in the application, and every action checks who’s signed in and what they’re allowed to do. Team members get their own logins and only see what the owner allows.
- Card payments run on Stripe; card numbers never touch our servers.
- Public forms are rate-limited and checked for abuse; uploads must be real images.
- Staff access to an account is read-only unless the owner grants edit access, expires automatically, and is shown in the owner’s activity log.
- Our hosting (Vercel) and database (Neon) providers maintain SOC 2 Type II reports.
Report a vulnerability
If you think you’ve found a security problem, please tell us through the contact form with steps to reproduce. Please don’t access other people’s data, disrupt the service, or share the issue publicly until we’ve fixed it. We won’t pursue good-faith research that follows these rules, and we’ll keep you posted.
If something goes wrong
If a breach affects personal information, we notify affected businesses without undue delay (see our Data Processing Addendum) and individuals and regulators as the law requires.
StellaBase
Questions or requests: use our contact form (or Help → Contact support in your dashboard). For a business’s own products or services, contact that business.