Account sessions
Brq uses authenticated sessions with HTTP-only cookies. Production session cookies are configured for secure transport.
Security
Brq applies practical controls appropriate to its current SaaS architecture. No certification or absolute-security guarantee is implied on this page.
Brq uses authenticated sessions with HTTP-only cookies. Production session cookies are configured for secure transport.
Supported payment-provider configuration is encrypted server-side with authenticated encryption before database storage.
Dashboard actions authorize the signed-in user or platform administrator before store data and management operations are exposed.
Sensitive card data is handled by the connected third-party payment provider. Brq does not store full card numbers or CVC/CVV values.
Merchants must protect their account credentials, restrict access to trusted users, maintain accurate provider credentials, and report suspected compromise promptly.
Send a reproducible description, affected URL, and potential impact to legal@brq.one. Do not access, alter, or disclose data beyond what is necessary to demonstrate the issue.