Security at KwataMove

We take the security of your business data and your customers' information seriously.

🔐

Encrypted in transit & at rest

All data encrypted with TLS 1.3 in transit. Database encrypted at rest.

🪪

Secure authentication

Session-based auth via Better Auth. HttpOnly cookies. No passwords stored in plaintext.

📷

Private photo storage

Move photos stored in private Cloudflare R2. Access via signed URLs only.

💳

PCI-compliant payments

Card data handled exclusively by Stripe. We never see or store credit card numbers.

🔒

Input validation & SQL injection prevention

All queries parameterized via Drizzle ORM. No raw SQL from user input.

🛡️

Security headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options configured on all responses.

Report a vulnerability

Found a security issue? Please report it responsibly to move@kwatateam.com. We respond to all security reports within 48 hours.