Skip to content

Trust

Security

Studios trust us with their calendar, their takings and their clients' details. Here is what we do to deserve that.

Data protection in transit and at rest

All traffic is served over TLS 1.2+. Data at rest is encrypted with AES-256. Secrets and API keys live in an encrypted store and are never committed to source control or exposed to the browser.

Access control

  • Row-level security on every table: a studio can only ever read its own records.
  • Role-based permissions inside the dashboard, owners, managers, front desk and staff each see a different slice of financial and client data.
  • Privileged operations run server-side only, after the caller's role is verified.

Payments

Card details are captured directly by our PCI-DSS Level 1 payment processor. Cover Beauty never sees or stores a full card number. Payouts and refunds are logged with an immutable audit trail.

Availability and backups

The platform runs on a globally distributed edge network with automated failover. Databases are backed up continuously with point-in-time recovery, and restores are tested regularly.

Monitoring

We run automated security scanning on every deploy, dependency vulnerability checks, and alerting on anomalous authentication and payment activity.

Your rights and data portability

Studios can export their bookings, clients and sales at any time. Deletion requests are honoured within 30 days, subject to the financial records we must retain by law.

Responsible disclosure

Found something? Email security@coverbeauty.co.uk with steps to reproduce. We acknowledge within two working days and will not pursue legal action against good-faith research that avoids privacy violations and service disruption.