Skip to main content
SECURITY & TRUST

Our security stance.

FaStart treats security, privacy, and operational trust as part of the product surface. This page describes the current controls and the boundaries we apply while the platform grows.

Last reviewed: July 13, 2026View platform status

PLATFORM SECURITY

fastart.tech ships HSTS, CSP, X-Content-Type-Options, Referrer-Policy, and restrictive permission headers.

Transport is encrypted, and production services are designed around least-privilege access and auditable changes.

We accept coordinated vulnerability reports through security@fastart.tech.

DATA AND AGENT BOUNDARIES

Visitor and contact data is handled under KVKK/GDPR-aligned principles.

Agentic product surfaces must preserve merchant control, logs, and override paths before they graduate from research.

Third-party services are reviewed for data handling, operational role, and necessity before adoption.

VULNERABILITY DISCLOSURE

Email: security@fastart.tech

PGP key: /.well-known/pgp-key.txt

Scope: fastart.tech (this site) and fastart.co (product). Out of scope: third-party services we use.

Response time: 24 h acknowledgement, 5 business days triage.

ASSURANCE ROADMAP

FaStart does not claim SOC 2, ISO 27001, PCI DSS, or other certifications on this corporate site. Any future assurance claim will link to verifiable scope and evidence.

Security controls, vendor review, incident response, and evidence retention are being documented before a certification program is announced.

PUBLIC PROCESSOR SUMMARY

Current corporate-site service categories include Vercel for hosting and edge delivery, Resend for configured contact email delivery, Plausible and consent-gated PostHog for analytics, Sentry for error monitoring, and Upstash for durable rate limiting. See the privacy notice for purposes and transfer details.

We use cookies. Essential ones keep the site working. Analytics ones help us understand what's useful. We don't use marketing cookies. Read our cookie policy