Security Policy
A marketplace for security products has to hold itself to the standard it sells. This is how the platform is built.
Accounts and access
Authentication is handled by a managed identity provider. Passwords are never stored in plaintext — only salted hashes held by that provider.
Two-factor authentication is available to every account and required for sellers and admins. Roles are enforced server-side, never from anything the browser can change.
Data protection
Row-level security policies scope every database read and write to the account that owns the row. Administrative queries run through audited, role-checked paths.
Uploads are restricted by type and size and are scanned before they are served.
Monitoring
Sign-in events, administrative actions and moderation decisions are written to an append-only audit log. Suspicious-login detection and rate limiting guard the authentication endpoints.
Payments
Card data is processed by the payment provider and never touches our servers. We store no raw card numbers or payment credentials.
Responsible disclosure
Report a suspected vulnerability through support with reproduction steps. Test only against your own account, never against other users' data, and give us a reasonable window to fix before publishing.
Sellers are solely responsible for ensuring they hold the legal right to sell every product and service they list on JOHNCODETECH.