SECURITY AT SHOP REGO

Protecting the record behind every repair.

Security is part of how Shop Rego is built and operated. This page describes the controls in place today and leaves out promises and certifications we have not earned.

CURRENT CONTROLS

What we can stand behind today

Encrypted transport

Shop Rego uses HTTPS at the gateway with managed TLS certificates.

Tenant isolation

Authenticated requests are scoped to the active organization, with authorization checks at the application boundary.

Protected credentials

Platform integration secrets are encrypted with AES-256-GCM under a master key held on the server and are never returned to the browser.

Revocable access

Staff sessions are revalidated and can be invalidated when an account, role, location, or organization status changes.

Audit records

Sensitive tenant and platform actions are recorded in immutable audit trails.

Recovery practice

PostgreSQL backups run on a schedule and restoration is checked by an automated drill.

Provider webhook verification

Supported provider callbacks use signatures or protected secrets and replay controls.

Customer document controls

Shared customer documents use expiring, revocable links and record access events.

HOW REPORTS ARE HANDLED

A direct path into Shop Rego HQ

Messages to the security address go to a dedicated HQ mailbox that sorts them by priority. We preserve the report, assess scope and impact, contain exposure where necessary, and communicate through the same thread.

View security.txt