Security at CartixAI
We take the security of your business data and your customers' information extremely seriously. Here's exactly how we protect you.
HTTPS / TLS Encryption
All communication between your browser, our servers, and third-party APIs uses TLS 1.2/1.3 encryption. We enforce HTTPS on all connections — there is no unencrypted HTTP access to CartixAI.
- TLS 1.2 / TLS 1.3
- HSTS enforced
- Automatic certificate renewal
Data Encryption at Rest
All data stored in our databases and file storage is encrypted at rest using industry-standard AES-256 encryption. Passwords are never stored in plain text — we use modern one-way hashing algorithms.
- AES-256 database encryption
- Password hashing (PBKDF2)
- Encrypted file storage
Payment Security
All payment processing is handled by SafePay, a licensed and regulated payment gateway in Pakistan. CartixAI never stores, transmits, or has access to your payment card numbers.
- PCI-compliant gateway (SafePay)
- No card data stored on CartixAI servers
- Tokenized payment references only
WhatsApp Security
CartixAI connects to WhatsApp Business API using official Meta Business APIs with OAuth and token-based authentication. Your WhatsApp credentials are stored encrypted and never exposed.
- Official Meta Business API only
- Encrypted token storage
- Disconnect anytime from dashboard
Cloud Infrastructure Security
Our infrastructure runs on enterprise-grade cloud providers with physical security, redundancy, and automated backups. We follow infrastructure-as-code practices to maintain consistent, auditable environments.
- Daily automated backups
- DDoS protection
- Network firewall & access controls
Access Control & Permissions
CartixAI implements role-based access control (RBAC) within businesses. Team members only see and access what their role permits. Admin controls who can do what within your account.
- Role-based permissions (RBAC)
- Team invitation system
- Secure session management
Report a Security Vulnerability
If you discover a security vulnerability in CartixAI, please report it responsibly. We take all security reports seriously and will investigate and respond within 48 hours.
[email protected]