Introducing the Pocketsflow startup program: Win $100K if you are a startupWin $100K if you are a startup

Security

Security without the compliance essay.

Pocketsflow protects creator and buyer data with industry standard controls, continuous monitoring, and clear ways to report issues.

How we operate.

We run a centralized compliance and security program that monitors controls, flags drift, and helps us remediate quickly. Branch protection, code review, automated tests, encryption, MFA, and access reviews are part of how we ship.

Certifications and frameworks.

These are the programs and frameworks we align with. Badge artwork in the footer links here for detail, not additional certifications beyond what is listed.

  • SOC 2 Type II

    Independent audit of security, availability, and confidentiality controls.

  • PCI DSS

    Payment Card Industry Data Security Standard for card processing.

  • ISO 27001

    Information security management system certification.

  • GDPR & CCPA

    Privacy frameworks for EU and California personal data.

  • EU to US Data Privacy Framework

    Transfer mechanism for personal data between the EU and the US.

  • HIPAA

    Safeguards for protected health information where applicable.

Payments and PCI.

Pocketsflow is PCI DSS compliant. We do not store raw card numbers on our servers. Sensitive payment data is tokenized; traffic uses TLS 1.2 or higher, and we support 3D Secure when required. Fraud systems help block abusive transactions.

  • No raw card storageTokens only.
  • Encryption in transitTLS 1.2 or higher.
  • Fraud checksMachine learning prevention plus 3DS where needed.

Data privacy.

Sensitive data is encrypted at rest and in transit. Access is least privilege, reviewed quarterly, and backed by background checks for new hires. Employees complete security training on join and annually. See our Privacy Policy and Data Processing Addendum for how personal data is handled.

  • Written security policies and incident response procedures
  • Annual third party web app penetration testing
  • Automated vulnerability scanning on code and dependencies
  • Intrusion detection and continuous access and traffic monitoring

Report a vulnerability.

If you find a security issue, email chain@pocketsflow.com with enough detail to reproduce it (URL or IP, steps, impact). We triage reports as quickly as we can and keep reporters updated.

Please do

  • Report privately before public disclosure
  • Share a minimal proof of concept only
  • Give us time to fix before publishing

Please don’t

  • Run automated scanners without asking for a sandbox
  • Access or modify other people’s data
  • Use DoS, social engineering, or physical attacks

Out of scope (examples)

Clickjacking, CSRF, MITM or physical access, DoS, email spoofing, missing DNSSEC, CAA, or CSP, insecure flags on nonsensitive cookies, dead links, DNS or email hardening alone, rate limiting, and XSS, plus anything else we designate out of scope. We will not take legal action against good faith reports that follow these rules; we keep reporter details confidential unless you ask to be credited.

Questions about security or compliance: chain@pocketsflow.com or Support.

Start accepting payments today.

Start accepting payments without building the infrastructure around them.