Security Practices

How PriceDepth protects your data, secures API access, and maintains infrastructure integrity.

Contents

  1. Infrastructure Security
  2. Application Security
  3. Data Security
  4. Operational Security
  5. Responsible Disclosure
  6. Compliance Roadmap
  7. Contact

Encrypted in Transit

All API traffic uses TLS 1.2+ encryption. No plaintext connections accepted.

WAF Protected

Cloudflare WAF filters malicious requests before they reach our servers.

API Keys Hashed

Keys stored as one-way hashes. Only the prefix is visible for identification.

Containerized

Services run in isolated Docker containers with minimal attack surface.

1. Infrastructure Security

2. Application Security

3. Data Security

4. Operational Security

5. Responsible Disclosure

We take security vulnerabilities seriously and appreciate responsible disclosure from the security research community.

Report a Vulnerability

If you discover a security vulnerability in PriceDepth, please report it responsibly.

[email protected]

Our Commitments

Scope

The following are in scope for responsible disclosure:

Please do not perform denial-of-service testing, social engineering, or access other users' data during your research.

6. Compliance Roadmap

We are committed to meeting the compliance requirements our enterprise customers need:

Current
GDPR Compliant Active
Full compliance with the EU General Data Protection Regulation. Data subject rights, lawful basis documentation, and data processing agreements in place.
Current
CCPA Compliant Active
Full compliance with the California Consumer Privacy Act. No sale of personal information. Consumer rights (access, deletion, opt-out) supported.
Q3 2026
SOC 2 Type I Planned
Independent audit of security controls design. Covers trust service criteria: security, availability, and confidentiality.
Q1 2027
SOC 2 Type II Planned
Independent audit of security controls effectiveness over a sustained period. Demonstrates operational maturity of security program.

Enterprise customers requiring specific compliance certifications or security questionnaires are encouraged to contact us at [email protected].

Contact