Security at Profitroomshop

How we protect your Profitroom API credentials, your account data and your module configuration from unauthorised access.

Encrypted API credentials

Your Profitroom API key is stored at rest with AES-256 symmetric encryption. The encryption key is held separately from the data in a dedicated key-management system. API keys are never written to logs in plain text.

TLS 1.3 in transit

All communication between your browser, the Profitroomshop platform and the Profitroom API uses TLS 1.3. Older TLS versions are not accepted. HSTS is enabled on the profitroomshop.org domain.

Access controls

Staff access to production systems follows the principle of least privilege. Support can view account metadata and billing data but cannot see API keys in plain text. Access to production data requires two-factor authentication.

Security testing

Profitroomshop undergoes annual penetration testing by an independent security firm. Critical vulnerabilities are patched within 72 hours. High-severity vulnerabilities within 14 days.

Incident response

In the event of a security incident affecting personal data, affected customers are notified without undue delay and within 72 hours when GDPR requires it. A public incident report is published within 30 days.

Responsible disclosure

Found a vulnerability? Email security@profitroomshop.org describing the issue. We respond within 24 hours and credit researchers who report a valid vulnerability responsibly.