SECURITY AT SHOP REGO

Protecting the record behind every repair.

Security is part of how Shop Rego is built and operated. This page describes controls that are in place today, not promises or certifications we have not earned.

CURRENT CONTROLS

What we can stand behind today

Encrypted transport

Shop Rego uses HTTPS at the gateway with managed TLS certificates.

Tenant isolation

Authenticated requests are scoped to the active organization, with authorization checks at the application boundary.

Protected credentials

Platform integration secrets are encrypted with AES-256-GCM under a server-held master key and are never returned to the browser.

Revocable access

Staff sessions are revalidated and can be invalidated when an account, role, location, or organization status changes.

Audit records

Sensitive tenant and platform actions are recorded in immutable audit trails.

Recovery practice

PostgreSQL backups run on a schedule and restoration is checked by an automated drill.

Provider webhook verification

Supported provider callbacks use signatures or protected secrets and replay controls.

Customer document controls

Shared customer documents use expiring, revocable links and record access events.

HOW REPORTS ARE HANDLED

A direct path into Shop Rego HQ

Messages to the security address enter a dedicated, priority-aware HQ mailbox. We preserve the report, assess scope and impact, contain exposure where necessary, and communicate through the same thread.

View security.txt