Security

Your data is safe with us.

Studio Splitz is built with security at every layer. From payment processing to file storage, we follow industry best practices to protect your studio, your team, and your clients.

PCI-Compliant Payments

All payment processing is handled by Stripe, the industry leader in payment security.

  • PCI DSS Level 1 certified through Stripe
  • Credit card numbers never touch our servers
  • 3D Secure authentication supported
  • Fraud detection and prevention built in

Data Encryption

All data is encrypted both in transit and at rest using industry-standard protocols.

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for stored data
  • Secure session management with HTTP-only cookies
  • Encrypted database connections

Infrastructure Security

Our platform runs on enterprise-grade infrastructure with multiple layers of protection.

  • Hosted on Replit's secure cloud infrastructure
  • Automated backups and disaster recovery
  • DDoS protection and rate limiting
  • 99.9% uptime SLA

File Storage Security

Session files are stored securely in Cloudflare R2 with enterprise-grade protection.

  • Cloudflare R2 with built-in encryption at rest
  • Signed URLs with expiration for file access
  • Isolated storage per studio account
  • Automatic malware scanning on upload

Authentication & Access

Multiple layers of authentication protect every account type on the platform.

  • OTP-based client authentication (passwordless)
  • Secure password hashing with bcrypt for studio accounts
  • Session-based authentication with secure tokens
  • Role-based access control (studio, contributor, client)

Privacy & Compliance

We respect your privacy and give you control over your data.

  • Granular email preference controls with unsubscribe
  • Data minimization - we only collect what's needed
  • No selling or sharing of personal data with third parties
  • Right to data deletion upon request

Our security practices

Secure Development

All code changes go through review processes. We follow OWASP guidelines for web application security and regularly audit our codebase for vulnerabilities.

Incident Response

We have documented incident response procedures. In the event of a security incident, affected users are notified promptly with clear information about the impact and remediation steps.

Vendor Security

We carefully vet all third-party services and integrations. Stripe, Cloudflare, and Google are all SOC 2 Type II certified providers with strong security track records.

Data Retention

We retain data only as long as necessary to provide our services. Session files, booking records, and account data can be deleted upon request. Payment records are retained as required by financial regulations.

Access Controls

Internal access to production systems follows the principle of least privilege. All administrative actions are logged, and access is reviewed regularly.

Responsible Disclosure

If you discover a security vulnerability, please report it to us through our contact page. We take all reports seriously and will respond within 48 hours.

Questions about security?

We're happy to answer any questions about how we protect your data.