Security, in plain English
How we secure your data
Every service runs behind a single API gateway that validates every request. Data sits in PostgreSQL with per-service isolation. Files are in S3 with presigned URLs that expire in 15 minutes. We sign and verify every webhook from Paystack. We rotate internal service secrets on a defined schedule.
How we secure access
Login is JWT-based with a Redis blacklist on logout. Email verification is required. Property managers have a role-based permissions system (RBHS) that scopes everything to the right property and the right person. We are migrating tokens out of browser storage and into HttpOnly cookies as a defence-in-depth step.
How we secure payments
We do not see card numbers. Paystack does. We see references and statuses. Paystack subaccount routing means landlord rent flows to the landlord without ever touching our balance sheet. The platform fee, when applicable, is extracted at the Paystack level using transaction_charge.
What happens if you find a bug
Email security@jarakey.com. Our /.well-known/security.txt records the disclosure path. We acknowledge serious reports within 48 hours and will credit reporters who ask to be credited. We do not paywall good-faith disclosures.