ConsignThem handles sensitive consigner financial records, addresses and photos. We take that seriously. Here's how.
TLS 1.3 between your browser and the API. PostgreSQL, R2 and Redis encrypted at rest. Magic-link tokens SHA-256, passwords bcrypt cost 12, TOTP secrets symmetrically encrypted.
Sellers sign in via magic link or TOTP — no password to forget, no credentials to leak. Admin sessions expire after 30 days idle.
Frankfurt + Berlin DCs. Cloudflare R2 (EU). Consistent GDPR jurisdiction, no cross-Atlantic data transfers, no Schrems II problem.
PostgreSQL WAL streaming + S3 cold snapshots every 24 h. Roll back to any point within the last 7 days.
Every payout, every cash-out sent, every price change → a record with timestamp + user + IP. No operation gets lost in a spreadsheet.
Each store has its own tenant scope. No SQL query can see another store's consigners, not even by accident. Regular penetration tests by an external firm.
Send the details to security@consignthem.com. Bug bounties are handled case-by-case — critical vulns up to €500. We never take down someone else's account, no matter who asks.
Back to sign-in