Security

The controls currently used to protect biocartly accounts, storefronts, payments, and platform operations.

Last updated: 17 July 2026

Account and platform safety concerns

support@biocartly.com

1. Identity and Access

biocartly uses a managed authentication service for account access. Dashboard and onboarding routes require an authenticated session.

Store access is permission-based across Owner, Admin, Manager, and Viewer roles. Each role receives only the platform actions assigned to it, and sensitive areas apply additional role checks where required.

2. Application and Browser Protection

The application defines HTTPS behavior. Browser-facing protections include a production Content Security Policy and policies that restrict framing, content-type sniffing, referrer information, and access to browser capabilities.

3. Credentials and Integrations

Sensitive payment-provider credentials stored by biocartly are protected using industry-standard authenticated encryption. This statement applies specifically to those credentials and is not a claim that every category of platform data uses the same protection.

The application verifies incoming integration and payment notifications before processing trusted events. Payment handling also includes reconciliation checks and regression coverage for supported flows.

4. Payment Data

Card payments are handled by external payment providers such as Yoco and PayFast. We do not store card numbers or CVV codes; biocartly retains the payment status and provider references needed to operate supported checkout and subscription flows.

5. Secure Development

Automated engineering checks run linting, type checking, tests, and production builds. Repository changes are also checked by automated secret scanning.

Dependencies are reviewed for known vulnerabilities, and security remediations are backed by focused regression tests or concrete configuration checks.

6. Monitoring and Service Status

biocartly uses application error monitoring to identify and investigate service problems. Current service information is available on our public status page.

7. Privacy and Service Providers

Our Privacy Policy describes our approach to South Africa's Protection of Personal Information Act (POPIA). Our Privacy Policy explains the information we process and the categories of operators used for authentication, hosting, payments, email, storage, monitoring, and other platform functions without publishing internal infrastructure details.

8. Report a Safety Concern

To report an account or platform safety concern, email support@biocartly.com. Include the affected page or account, what you observed, and steps that help us reproduce the concern. Do not include passwords, payment card details, or other secrets.