Security & Trust

Security controls you can trace

These statements are scoped to controls the application repository can substantiate. Each one has an accountable owner, a review date, and mapped automated evidence.

Scope of this assurance page

This page describes application and repository controls that can be traced to maintained code and automated checks. It does not assert production backup retention, point-in-time recovery, provider certifications, branch-protection settings, or other deployment controls that are not verified from this repository.

Current control statements

A repository check rejects stale reviews, missing evidence, disabled gate wiring, and categorical wording that exceeds the mapped control.

PAY-01

Card entry is delegated to Stripe

Gotlan checkout and fee-payment forms collect card details in Stripe.js Elements. The application passes Stripe payment-method identifiers to server actions instead of collecting raw card numbers or CVC values in Gotlan form fields.

Control owner
Payments Engineering
Last reviewed

Mapped evidence

  • Stripe Elements card-entry boundary
  • Production payment-provider safety suite
STO-01

Delivery files remain in connected Dropbox storage

Finished delivery files and generated MLS copies remain in the vendor team's connected Dropbox. Gotlan stores source paths, application download routes, file sizes, and delivery metadata, and may retrieve or transform a file to serve an authorized preview or download. Removing a connection deletes Gotlan's locally stored Dropbox grant; the files remain in the team's Dropbox.

Control owner
Media Integrations
Last reviewed

Mapped evidence

  • Dropbox delivery synchronization
  • Authorized short-lived delivery download
  • Bounded preview transformation
  • Dropbox disconnect authorization suite
AUTHZ-01

Protected flows enforce server-side access checks

Protected order, client, file, and administrative flows use server-side identity, role, team, and resource checks. Automated tenant-isolation and endpoint suites exercise the catalogued boundaries; this is a tested control, not a claim that authorization defects are impossible.

Control owner
Application Security
Last reviewed

Mapped evidence

  • Shared tenant authorization helpers
  • Tenant-isolation integration suite
  • RBAC endpoint integration suite
DATA-01

Selected high-risk fields have application-layer protection

Gotlan encrypts connected-account tokens and property or booking access secrets before database writes when the production encryption key is configured. Error telemetry disables default PII collection and passes events through application redaction before sending when monitoring is enabled.

Control owner
Application Security
Last reviewed

Mapped evidence

  • Sensitive-field encryption boundary
  • Server telemetry redaction boundary
  • Browser telemetry redaction boundary
  • Edge telemetry redaction boundary
  • Sensitive-field encryption suite
  • Telemetry privacy suite
SDLC-01

Repository checks are scoped and explicit

For application changes targeting main or develop, repository CI is configured to run build, typecheck, tests, tenant-isolation, RBAC, security, audit-scan, and public E2E checks. A separate gitleaks job is configured to fail on detected secrets. The current lint step and Semgrep SAST workflow are report-only and are not represented as release blockers.

Control owner
Engineering Productivity
Last reviewed

Mapped evidence

  • Main application CI workflow
  • Blocking secret-scan workflow
  • Public assurance drift suite

Free CRM. Your data, your files, your terms.

Create your free account

Free CRM. No credit card. Keep your own clients at 0%.