All traffic is served over TLS. Passwords are hashed with bcrypt and never stored in plaintext. Sessions use HTTP-only cookies. Payment card data is handled entirely by Stripe and never touches Lyncta servers. Infrastructure runs on AWS in the us-east-1 region.
Staff accounts on the Business plan use scoped permissions so team members only reach the features they are granted. Rate limiting and a Helmet-based Content Security Policy are applied at the edge of the API.
Report a suspected vulnerability to security@lyncta.com. We acknowledge reports within three business days. Please do not test against other customers accounts or public profiles.