Security
Last updated: July 18, 2026
Your shop's records are your business. Here is how we protect them, in plain language.
Your data is yours alone
Every shop's data is kept fully separate from every other shop's. That isolation is enforced at the platform's core, not bolted on, and every release is automatically tested to prove one shop can never see another shop's data.
Encryption everywhere
- All traffic between you and ScubaShop is encrypted in transit.
- Backups are strongly encrypted before being stored offsite.
- Files (waivers, photos, documents) live in private storage that is never publicly accessible.
Backups you could actually restore
Your data is backed up continuously, not just nightly: we can restore to within minutes of any point in time, and we maintain and test a written recovery plan so a restore is a procedure, not an improvisation.
Payments
Card data never touches our servers. Payments are processed by Stripe (a PCI DSS Level 1 provider) on your shop's own Stripe account; we store only payment references.
Access control
- Role-based access inside each shop (owner, manager, finance, payroll, staff), so staff see only what their role allows.
- Two-factor authentication available for accounts.
- An append-only event log records who did what, including permission overrides.
- Login attempts are rate-limited against brute force.
Ongoing vigilance
The platform is monitored around the clock, software and dependencies are continuously scanned for known vulnerabilities before they ship, and we keep the surface a customer-facing product exposes deliberately small.
Reporting a vulnerability
If you believe you have found a security issue, email security@scubashop.io with the details. We read these first and respond quickly, and we will not take action against good-faith research that respects other shops' data.

ScubaShop