Security & Data Protection Controls
At Vaarep, protecting customer data, business records, and Google API integrations is a fundamental technical priority.
Data Encryption in Transit & At Rest
All web traffic to and from Vaarep is enforced over HTTPS using TLS 1.3 encryption. Sensitive credentials and database fields are encrypted at rest using industry-standard AES-256 encryption.
Strict Multi-Tenant Isolation
Every organization operates within an isolated tenant workspace. All database queries enforce organization boundaries to prevent cross-tenant data leakage.
Session Authentication & Access Control
Authentication is managed via secure, HTTP-only session tokens with strict CSRF and XSS protection. User accounts support explicit Role-Based Access Control (RBAC).
Secure Payment Gateway Integration
Vaarep does not store raw credit card numbers or banking secrets. Payment transactions are processed directly by PCI-DSS compliant providers (Paddle for Global USD; PayFast and Paystack for South Africa ZAR).
Google Business Profile OAuth 2.0
Google Business Profile connections utilize official Google OAuth 2.0 tokens scoped strictly to review management permissions, stored securely in encrypted application settings.
System Audit Logs & Monitoring
Critical admin actions, settings edits, checkout events, and authentication changes generate immutable audit log records to track operational activity.
Security Practices & Certification Notice
Vaarep implements rigorous technical controls, code reviews, and dependency vulnerability scanning. We state our security architecture accurately based on our current operational deployment. We do not claim unverified SOC 2, ISO 27001, or HIPAA certifications. For vulnerability disclosures or security questions, contact our security team at privacy@vaarep.com.