Skip to main content
Waine Appointments

Security

Protecting your business data and your clients' information is foundational to everything Waine does. Here is how we keep your data safe.

Encryption in transit and at rest

Waine uses HTTPS with modern TLS to protect data in transit. Production data is stored on managed infrastructure that provides encryption at rest. Specific infrastructure controls are reviewed with enterprise customers on request.

Password security

Passwords are hashed with bcrypt (cost factor 12) before storage. Waine never stores plaintext passwords. Password reset tokens are single-use and expire in 15 minutes.

Two-factor authentication

All user accounts can enable two-factor authentication (2FA) via email or SMS. Business owners are encouraged to enable 2FA on initial setup. Recovery codes are provided at enrollment.

Audit logging

Waine records selected administrative and operational events to support security review and incident investigation. Audit records are restricted to authorized administrative access. The current log does not include cryptographic immutability controls.

Login alerts

When a sign-in is identified as new based on device and IP history, Waine attempts to send a security alert email. Where password sign-in is enabled, the alert includes a short-lived password-reset link.

Infrastructure

Waine runs on Railway-managed infrastructure. Railway publishes its security and compliance posture, including its SOC 2 Type II attestation, through its trust documentation. Waine does not claim that a provider attestation certifies Waine itself.

PCI compliance via Stripe

Waine does not store credit card numbers, CVVs, or full payment details. All card processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Waine receives only tokenized references.

Privacy practices

Waine uses purpose limitation, data minimization, access controls, and documented request channels to support business privacy obligations. See our Privacy Policy for details.

Read our Privacy Policy

Breach notification

In the event of a confirmed data breach affecting your business, Waine will notify affected businesses and, where required, regulators or individuals in accordance with applicable law.

Responsible disclosure

Security researchers who discover a vulnerability in Waine are encouraged to report it responsibly. We commit to acknowledging reports within 2 business days and to not pursuing legal action against good-faith disclosures.

security@waineappointments.com

Questions about our security practices?

We are happy to answer questions from business owners, enterprise buyers, or privacy officers.

security@waineappointments.com

Last reviewed: September 8, 2026 · Privacy Policy · Canadian Privacy · Terms of Service