Trust
Security posture
MyPet Club is designed as a multi-tenant service with tenant-scoped authorization and host-isolated sessions. Its automated checks include negative tenant-isolation tests, contract validation, application builds, end-to-end smoke tests, and accessibility checks before changes reach production.
Current safeguards
- Managed authentication, database controls, and row-level tenant isolation.
- Least-privilege service access and separate production secrets.
- Transport encryption and managed encryption at rest where supported by the provider.
- Validated Stripe events and append-only records for material payment facts.
- Audit records for sensitive administrative and financial actions.
- Logging and telemetry designed to exclude passwords, one-time codes, full payment credentials, and QR payloads.
- Automated dependency, unit, integration, browser, and tenant-isolation testing.
Payments
Stripe handles payment-card and bank-account details. MyPet Club stores processor references and transaction facts rather than full card or bank-account numbers.
Responsible disclosure
Please report a suspected vulnerability to security@mypetclub.pet. Include a clear description, affected URL or feature, reproduction steps, and impact, but do not include personal data or exploit other users. We will acknowledge and investigate good-faith reports.
We do not currently claim an independent security certification, guaranteed uptime, a public bug bounty, or immunity from incidents. Security questions may be sent to the same address.