Security
How we protect your data and our commitment to security.
Last updated: June 5, 2026
1. Security Practices
Security is part of how Fesk is built. We use several layers of protection for customer data:
- All data transmitted over HTTPS with TLS 1.2+ encryption
- Sensitive session data encrypted at rest
- CSRF protection on all state-changing requests
- Rate limiting to prevent brute-force and abuse attacks
- Input sanitization and suspicious input detection
- Role-based access control (RBAC) on all protected endpoints
- Content Security Policy (CSP) headers enforced in production
2. Infrastructure Security
Our infrastructure is designed for reliability and security:
- Hosted on hardened, regularly patched servers
- Secure, parameterized database access protects against manipulated queries
- API keys stored as cryptographic hashes, never in plaintext
- Automated daily database backups retained on a rolling basis for up to 30 days and then automatically overwritten or deleted
- Health monitoring with automated alerting
3. Payment Security
Payment processing is handled by an external PCI DSS-compliant payment service provider. Fesk does not store, process, or transmit complete credit card numbers. Payment data is processed directly through the provider's protected payment fields.
4. Authentication and Access
- Secure session management with encrypted session storage
- Email verification required for new accounts
- Time-limited tokens for password reset and invitation flows
- Registration abuse protection with rate limiting, mandatory email verification, and abuse detection
- Audit logging of all authentication events
5. Vulnerability Disclosure
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:
- Email: security@fesk.io
- Please include a detailed description of the vulnerability and steps to reproduce
- We will acknowledge receipt within 48 hours
- We aim to resolve confirmed vulnerabilities within 30 days
Please do not publicly disclose vulnerabilities until we have had an opportunity to address them.
6. Data Residency and Hosting
You select a deployment region during registration, and we store your primary workspace data in that region. Infrastructure is provided through professional cloud services. Some sub-processors may process limited data in other countries to provide the Service; where this involves a transfer out of the EEA, we apply appropriate safeguards. See our GDPR page for the current list of sub-processors and transfer mechanisms.
7. Data Protection
Our data protection practices include:
- Data encrypted in transit and at rest
- Access to production systems restricted to authorized personnel
- Regular security reviews based on recognized web application standards
- Dependency scanning for known vulnerabilities
For details on how we handle personal data, see our Privacy Policy and GDPR/Data Protection page.
8. Contact
For security-related inquiries, email security@fesk.io. For general support, visit our Contact page.