Loading JapaReady
Preparing your personalized workspace.
Loading JapaReady
Preparing your personalized workspace.
Contact: security contact form
JapaReady is designed to rely on TLS 1.3 for data in transit through managed platform services and encrypted-at-rest storage controls offered by infrastructure providers.
Authentication is handled through Supabase Auth with managed session handling. Optional MFA and expanded account hardening features are on the roadmap rather than represented as live everywhere today.
We do not sell personal data. Access to user information is limited to what is necessary for service delivery, support, and security operations.
We perform routine engineering review of security-sensitive changes. A broader responsible disclosure process and formal recurring penetration testing are planned as the platform matures.
Traffic protection relies primarily on the safeguards available through our hosting and API infrastructure. Additional application-layer protections are part of the hardening roadmap.
User data is stored through managed infrastructure with encrypted storage, backups, and role-based access controls where supported by the providers in use.
Security headers, WAF-style controls, and threat-monitoring posture depend on deployment configuration. We only describe them as active when they are configured in the live environment.
Application sessions are managed through Supabase. Password hashing and low-level credential handling are provided by the authentication provider rather than implemented directly in the app layer.
Full card data is never stored directly by JapaReady. Payments are processed through PCI DSS Level 1 providers including Paystack, Flutterwave, and Paddle.
Report vulnerabilities through /contact?category=security rather than disclosing publicly. We acknowledge all reports within 24 hours.
Regular penetration testing is planned. We do not claim completed external audits until they have actually been conducted.