Security
How we protect your data, your margins, and your customers.
Floor price guard
Your floor price is stored server-side only. It is never placed in the AI prompt or sent to the browser, making it immune to prompt injection. Every agreed price is re-validated against the floor before any checkout link is created.
Tamper-proof checkout
Checkout URLs are HMAC-signed, so the agreed price cannot be modified in transit. Signatures are verified using constant-time comparison.
Authentication
- Passwords are hashed with bcrypt; we never store them in plain text.
- Dashboard sessions use signed, httpOnly cookies with a strong server secret.
- Admin areas are role-gated on both the server and the API.
Infrastructure
- All traffic is served over HTTPS.
- Database access is restricted; row-level security is enabled on stored tables.
- Rate limiting and input validation protect every API endpoint.
- Internal error details are never leaked to clients.
Reporting a vulnerability
Found something? We appreciate responsible disclosure. Email security@negotiobot.comand we'll respond promptly.