← Back to home

Security

Your studio data — and your clients' personal information — is handled with care. Here's exactly what we do to protect it.

Data protection

Access controls

Infrastructure

Payment security

Deposits and subscription payments are processed by Stripe, which is PCI DSS Level 1 certified. Card numbers never pass through ServaloDesk servers — they go directly from the client's browser to Stripe's servers. We store only Stripe's tokenised payment method references and transaction IDs.

Content Security Policy

All pages are served with a strict Content Security Policy that disallows inline JavaScript and restricts which external domains can load resources. This mitigates XSS attacks even if an injection vulnerability were found.

Responsible disclosure

If you've found a security vulnerability in ServaloDesk, please report it to us before disclosing it publicly. We'll acknowledge your report within 24 hours and work to resolve confirmed vulnerabilities promptly.

Email: [email protected]

Please include a description of the issue, steps to reproduce, and your assessment of impact. We don't operate a bug bounty programme at this time, but we'll credit reporters in our changelog (with your permission).