Security
How smbnest protects your account and your data.
Encryption
All traffic between you and smbnest is encrypted in transit using TLS. Data is encrypted at rest by our managed infrastructure providers.
Authentication and access
Passwords are never stored in plain text - they are hashed using a modern, salted algorithm. Sessions use secure, signed cookies, and the application enforces cross-site request forgery (CSRF) protection on sensitive actions. Internal administrative access follows the principle of least privilege.
Payments
Subscription payments are handled by Stripe, a PCI-DSS Level 1 certified provider. smbnest never receives or stores your full card number.
Infrastructure
smbnest runs on reputable cloud platforms with managed, regularly backed-up databases. We apply security updates promptly and separate our production environment from development work.
Data minimization and monitoring
We collect only the information we need to run the service, and we monitor for unusual or abusive activity. For more on what we collect and how we use it, see our Privacy Policy.
Responsible disclosure
If you discover a potential vulnerability, we want to hear from you. Please email hello@smbnest.com with the details, and we will acknowledge your report and work to address it. Please give us a reasonable opportunity to respond before any public disclosure.
Our commitment
smbnest is an early-stage product, and security is something we treat as ongoing work rather than a finished checkbox. We are continually strengthening our practices and will pursue formal third-party certifications as the platform grows.