Security

How we protect your data, your margins, and your customers.

Floor price guard

Your floor price is stored server-side only. It is never placed in the AI prompt or sent to the browser, making it immune to prompt injection. Every agreed price is re-validated against the floor before any checkout link is created.

Tamper-proof checkout

Checkout URLs are HMAC-signed, so the agreed price cannot be modified in transit. Signatures are verified using constant-time comparison.

Authentication

  • Passwords are hashed with bcrypt; we never store them in plain text.
  • Dashboard sessions use signed, httpOnly cookies with a strong server secret.
  • Admin areas are role-gated on both the server and the API.

Infrastructure

  • All traffic is served over HTTPS.
  • Database access is restricted; row-level security is enabled on stored tables.
  • Rate limiting and input validation protect every API endpoint.
  • Internal error details are never leaked to clients.

Reporting a vulnerability

Found something? We appreciate responsible disclosure. Email security@negotiobot.comand we'll respond promptly.