Sign inGet started

Security

Last updated: June 2026

PRVNTR is built to keep your business data isolated and your credentials out of reach of anyone but you. Here's a plain-language rundown of what's actually in place today.

Authentication

Sign-in is handled via email one-time codes, Google OAuth, or GitHub OAuth — we never store your password. Sessions use short-lived JWT access tokens (15 minutes) paired with opaque refresh tokens (30 days) that are hashed before they ever touch our database.

API Keys

Each business can generate one API key for connecting an external storefront. The full key is shown to you exactly once, at creation time. After that, we only ever display a short, non-secret prefix — the key itself is hashed (SHA-256) before storage, the same way we treat refresh tokens.

Access Control

Every action is scoped to a role — owner, admin, or member — and every piece of data (items, categories, offers) is scoped to a single business. There's no cross-business access: a member of one business has no visibility into another's data.

Reporting a Concern

If you believe you've found a security issue, reach out to contact@prvntr.com and we'll follow up as quickly as we can.