Skip to main content

Built to be trusted.

We take the security of your data seriously, so you can run your scheduling, payments, and client data on magtyne cadence with confidence.

Your data

What we store is encrypted, isolated per company, and access is scoped and logged.

Encrypted in transit and at restEvery request runs over HTTPS with HSTS preload. Integration tokens and secrets are encrypted at rest with AES-256-GCM.
Per-tenant data isolationEvery query is scoped to a single workspace. One workspace can never read or write another workspace’s data.
Role-based access controlOwner, admin, member, and viewer roles let you grant only the access each person needs, and nothing more.
Audit log of changesChanges are recorded in an audit log, so you can see what happened, when, and who did it.

Accounts and access

Sign-in is protected by strong hashing, second factors, and lockouts on abuse.

Hashed passwords and keysPasswords are hashed with bcrypt. API keys are stored only as hashes, never in plain text.
Two-factor authenticationTurn on TOTP two-factor authentication, with one-time recovery codes that are themselves hashed.
Brute-force protectionPer-IP and per-account login lockouts slow down and stop repeated password guessing.
SAML SSO and SCIM (available on request)Larger teams can request SAML single sign-on and SCIM provisioning. Data export is available on request.

The platform

The application ships with hardened defaults and guards on every request in and out.

Strict security headersContent-Security-Policy, X-Frame-Options with frame-ancestors, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are set across the app.
Rate limitingRate limits across the API surface keep automated abuse and traffic spikes from affecting your workspace.
Signed, guarded webhooksIncoming payment webhooks are signed and verified. Outbound webhooks are signed and guarded against SSRF.
Least-privilege secretsInfrastructure secrets live in environment variables, never in code, so credentials stay out of the codebase.

Payments

Card details are handled by the payment providers directly, and the money is yours.

Card data never touches our serversPayments run through Stripe, Square, or PayPal directly. Card details go to the provider, not to us.
PCI-compliant providers, no platform feePayments are processed by PCI-compliant providers. You connect your own account and we take no platform fee on your bookings.

Responsible disclosure

Found a security issue? We want to hear about it. Our policy is published at /.well-known/security.txt, and you can reach the team directly by email.

support@magtyne.com

A note on certifications: payments are processed by PCI-compliant providers such as Stripe. We do not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification of our own, and we would rather be plain about that than imply otherwise.

Make scheduling yours.

Set up your first booking page in minutes. Branded, time-zone honest, and ready to take payment.