IsCarTi

Security

How we protect your records.

Your car's history includes invoices, and sometimes names, addresses and phone numbers. Here is what we actually do to protect it, in plain terms.

Signing in

  • You sign in with a link sent to your email. There is no password to steal, reuse or forget.
  • You can sign out on every device at once from your profile.

Your documents and records

  • Uploaded documents are kept in private storage. Only you can open them, through links that expire after an hour.
  • The database enforces who can see what. You can only reach your own data, and this is checked by automated tests, not left to the screens.
  • Trust levels, plan limits and payments are decided by the server. Nothing in the browser can grant itself a verified badge or a paid plan.
  • A shared history shows only the timeline. Documents are never included, and you can hide costs.

Payments

  • Payments are handled by PayFast. Card and bank details are entered on their page and never reach our servers.
  • We only activate a plan after checking PayFast's signed confirmation, and that the amount matches what we asked for.

Your control

  • Download everything we hold about you, or delete your account and every file, on your account page.
  • We use only the cookies needed to keep you signed in. There are no advertising or tracking cookies. See the privacy policy.
  • Only a one-way fingerprint of a record ever leaves the database for timestamping. No readable data is published.

Being honest about it

No system is perfectly secure, and IsCarTi is new. We have not yet had an independent security audit. We build carefully and test the rules that protect your data, but we'd rather say so than overclaim.

Found a problem?

If you think you've found a security issue, please tell us privately before making it public, so we can fix it first. Use the contact form and choose “A problem”. Our machine-readable policy is at /.well-known/security.txt. We will not take action against people who report in good faith.