TLS 1.3
Transport encryption
AES-256
At-rest encryption
SOC 2
Infrastructure compliance
PCI DSS
Via Stripe
2FA
Account security
RLS
Database isolation
Our Security Practices
Encryption Everywhere
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. This includes your client records, booking data, and payment information.
SOC 2 Infrastructure
We run on Supabase and Vercel — both SOC 2 Type II certified platforms with rigorous access controls, audit logging, and 99.9% uptime SLAs.
Zero Data Selling
We will never sell, rent, or broker your personal data or your clients' data. Your data is used solely to operate and improve the Service.
Access Controls
Row-level security enforces strict data isolation between practitioners. No practitioner can access another's data. Internal access requires MFA and audit trail.
Incident Response
We maintain a documented incident response plan. In the event of a confirmed data breach affecting your personal data, we will notify affected users within 72 hours of discovery, consistent with GDPR Article 33 requirements.
Our security team monitors platform activity 24/7 using automated anomaly detection. All production systems generate immutable audit logs retained for 12 months.
Responsible Disclosure
If you've discovered a security vulnerability in MysticsPortal, we want to hear from you. We request that you:
- Report the issue privately before any public disclosure
- Give us reasonable time (90 days) to investigate and remediate
- Avoid accessing, modifying, or deleting any user data
We will acknowledge receipt within 24 hours and keep you updated throughout our investigation. We do not currently offer monetary bug bounties, but we will credit researchers (with permission) in our changelog.
Found a vulnerability?
Report it to our security team — we take every report seriously.