Security
Last updated: June 2026
PRVNTR is built to keep your business data isolated and your credentials out of reach of anyone but you. Here's a plain-language rundown of what's actually in place today.
Authentication
Sign-in is handled via email one-time codes, Google OAuth, or GitHub OAuth — we never store your password. Sessions use short-lived JWT access tokens (15 minutes) paired with opaque refresh tokens (30 days) that are hashed before they ever touch our database.
API Keys
Each business can generate one API key for connecting an external storefront. The full key is shown to you exactly once, at creation time. After that, we only ever display a short, non-secret prefix — the key itself is hashed (SHA-256) before storage, the same way we treat refresh tokens.
Access Control
Every action is scoped to a role — owner, admin, or member — and every piece of data (items, categories, offers) is scoped to a single business. There's no cross-business access: a member of one business has no visibility into another's data.
Reporting a Concern
If you believe you've found a security issue, reach out to contact@prvntr.com and we'll follow up as quickly as we can.