Protected account actions
Passwords are salted and strengthened with PBKDF2. Sessions use secure, HTTP-only cookies, expiration, same-origin checks, and per-session request tokens.
A redirect service is a trust service. ScanSteer separates the public scan path from protected account tools and collects only the analytics needed to make the product useful.
Passwords are salted and strengthened with PBKDF2. Sessions use secure, HTTP-only cookies, expiration, same-origin checks, and per-session request tokens.
Every dashboard operation verifies organization membership on the server. Database queries never rely on a hidden button as access control.
Daily visitor estimates use a one-way keyed hash. Raw IP addresses are discarded rather than saved in analytics records.
ScanSteer uses Stripe-hosted Checkout and the Customer Portal. Card details never pass through or live in the ScanSteer database.
Please report it privately to security@scansteer.com. Include enough detail for us to reproduce it, and do not access data that is not yours.