Last updated: July 2026
Security is core to how we build SellFlow. This policy describes the safeguards we use to protect seller and buyer data, and how security researchers can responsibly report a vulnerability.
SellFlow runs on managed, industry-standard cloud infrastructure — Google Firebase for authentication and data storage, and Vercel for application hosting and content delivery. These providers maintain their own certified physical, network, and platform security controls.
All traffic to and from the platform is encrypted in transit using HTTPS/TLS. Sensitive data, such as seller payment-profile details, is encrypted before storage. Access to production data is restricted to authorized personnel on a need-to-know basis, and administrative access is protected by strong authentication.
Buyer and seller data is segmented by ownership. Database access is governed by server-enforced security rules so that sellers can only read and write their own records, and privileged operations run through authenticated server-side routes rather than the client. Public order creation is handled server-side to prevent tampering.
We use bot detection, shielding, rate limiting, and geo controls on sensitive endpoints to defend against automated attacks, credential stuffing, scraping, and denial-of-service attempts. Suspicious activity is logged and reviewed, and admin surfaces are protected by additional authentication layers.
Protect your account by using a strong, unique password, keeping your login and recovery contacts current, and never sharing credentials. Notify us immediately if you suspect unauthorized access to your account.
We welcome reports from security researchers. If you discover a vulnerability, please email support@sellflow.bio with steps to reproduce, and give us reasonable time to investigate and fix the issue before any public disclosure. Please do not access or modify data that is not yours, degrade the service, or run destructive tests. We will acknowledge valid reports and work with you in good faith. Acting in good faith under this policy, we will not pursue legal action for your research.
If a data breach affects your personal data, we will investigate, contain, and remediate the incident, and notify affected users and regulators where required by applicable law and within the timeframes it sets.
For any security concern or disclosure, contact support@sellflow.bio.