Security

Security by design.

We keep the system small, encrypt what matters, and lean on proven providers for the hard parts — so your data and your clients’ payments stay protected.

Encrypted in transit Payments handled by Stripe (PCI) Access scoped to your account Sign-in secured by Google

How we protect your data

The essentials, done properly.

Nothing exotic — just the controls that actually matter for software that touches money, applied consistently.

Payments

Card and ACH payments run through Stripe. Raw card numbers never touch our servers — Stripe handles them under PCI DSS.

Encryption

Traffic is encrypted in transit with TLS, and data is encrypted at rest by our infrastructure providers.

Authentication

Sign-in is handled by Google’s Firebase Authentication, including Google sign-in, with secure server-side sessions.

Access control

Your data is scoped to your account and visible only to authenticated users you’ve invited. No cross-account access.

Proven providers

We don’t reinvent the hard parts. Payments, auth, and hosting run on Stripe and Google — companies that secure this at scale.

Reliability

Tabulox runs on reputable cloud infrastructure with regular backups, so your records stay available and recoverable.

Responsible disclosure

Found a security issue? Tell us.

Security is never finished. If you believe you’ve found a vulnerability in Tabulox, let us know and we’ll work with you to confirm and fix it.

Report a vulnerability

Email us directly. We aim to acknowledge reports within a few business days and to keep you updated as we investigate. We won’t pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us reasonable time to resolve the issue before going public.

Security contact
security@sparkleintelligence.com
Email security

Please include

  • Clear steps to reproduce the issue
  • The impact you believe it has
  • A way for us to reach you with follow-ups

Please avoid

  • Accessing or modifying data that isn’t yours
  • Service disruption, spam, or automated attacks
  • Sharing the issue publicly before it’s fixed

Questions

Want more detail?

For privacy specifics, see our Privacy Policy and Cookie Policy. For anything else about how we protect your account, reach us on the contact page.