Security

Security without unsupported claims.

Brq applies practical controls appropriate to its current SaaS architecture. No certification or absolute-security guarantee is implied on this page.

Account sessions

Brq uses authenticated sessions with HTTP-only cookies. Production session cookies are configured for secure transport.

Integration credentials

Supported payment-provider configuration is encrypted server-side with authenticated encryption before database storage.

Scoped access

Dashboard actions authorize the signed-in user or platform administrator before store data and management operations are exposed.

Provider separation

Sensitive card data is handled by the connected third-party payment provider. Brq does not store full card numbers or CVC/CVV values.

Merchant responsibilities

Merchants must protect their account credentials, restrict access to trusted users, maintain accurate provider credentials, and report suspected compromise promptly.

Report a security issue

Send a reproducible description, affected URL, and potential impact to legal@brq.one. Do not access, alter, or disclose data beyond what is necessary to demonstrate the issue.