Tenant boundaries
Organization and workspace boundaries are enforced on the server, with permission checks for sensitive actions.
Security
CoinDealerPro is built for operational and financial data. Its security model starts with server-enforced isolation, deliberate permissions, and evidence-preserving workflows.
Organization and workspace boundaries are enforced on the server, with permission checks for sensitive actions.
The application is configured to require HTTPS in deployed environments. Provider credentials and API tokens stay server-side and are not sent to the browser.
Role-based permissions separate viewing, creating, editing, approving, exporting, and administrative work.
Material business actions create audit evidence. Posted financial corrections preserve the original record.
Stripe-hosted checkout and billing portal handle payment-card collection. Signed webhooks are verified before billing state changes.
Backup, restore, key, provider, and rollback checks are explicit launch gates. Production recovery is not represented as validated until operating evidence exists.
Responsible disclosure
Email a clear description, affected URL, reproduction steps, and potential impact. Do not access another customer’s data, degrade service, or publish an unresolved issue.
Report a security issue at sales@coindealerpro.comThese statements describe implemented application controls and the documented launch model. They are not a certification, a claim of perfect security, or a claim that production recovery has been validated. Formal audit material is provided only when it actually exists.