Security

Security is part of how Pageey is operated.

Pageey is designed to limit access to business data, separate merchant access from platform administration, and reduce unnecessary exposure of connected-platform credentials and operational data.

Transport security

Public Pageey web properties are served over HTTPS. Pageey's public website enforces modern browser security headers and is intended to reject insecure transport.

Authentication and sessions

Application access is authenticated and session based. Administrative access is separated from merchant access and supports two-factor authentication, session revocation and protected administrative routes.

Administrative controls and audit

Sensitive platform operations are limited to authorized administrative roles. Administrative actions such as suspending or reactivating access and revoking sessions are designed to be auditable.

Connected platforms

Third-party business platforms are connected only after explicit authorization. Pageey aims to request and use only the permissions needed for the selected integration and does not publish access tokens or credentials in public pages.

Data minimization

Operational and support tooling is designed to avoid exposing message content, secrets or credentials when diagnostic metadata is sufficient.

Report a security concern

Security reports can be sent to developer@pageey.com. Please include enough information for us to reproduce and investigate the issue, and do not publicly disclose sensitive details before we have had a reasonable opportunity to investigate.

Security contact is published at /.well-known/security.txt