Karatrack

Trust & Security

How we protect your data

A plain-English overview of the measures that keep Karatrack accounts, shows, and payments safe.

Karatrack is built for venues and hosts who trust us with their shows, their singers, and their business. This page explains, without jargon, how we protect that trust — and it describes what is actually built into our systems today, not aspirations.

Encryption everywhere

Every connection to our websites and apps is encrypted (HTTPS with HSTS), and data is encrypted at rest by our cloud infrastructure. There is no unencrypted way to reach a Karatrack service.

Your card details never touch our servers

All payments are processed by Stripe, a certified payment provider used by millions of businesses. Card numbers go directly to Stripe — we never see them and never store them.

Account protection

Passwords are stored only as salted, deliberately slow one-way hashes (bcrypt) and are screened against known-breached-password lists whenever they are set, in line with the NIST SP 800-63B-4 Digital Identity Guidelines. Singer accounts require at least 8 characters; venue-owner and admin accounts, which hold business data, require at least 15. Repeated failed logins temporarily lock the account, verification codes allow only a few attempts, and password-reset links expire quickly and are stored hashed.

Hardened infrastructure

Karatrack runs on established cloud platforms (Vercel, Cloudflare, Supabase, Neon). Every administrative account is protected by multi-factor authentication, and our software dependencies are monitored automatically for known vulnerabilities.

Private files stay private

Sensitive uploads are kept in private storage and can only be opened by their authorized owner, through links that expire within minutes.

If something goes wrong

We maintain a documented incident response plan. If a breach ever affects your personal data, we will notify you within 72 hours of confirming it and tell you plainly what happened and what we did about it.

Found a security issue?

We welcome good-faith security research. Report vulnerabilities to security@karatrack.com and we will respond within 3 business days. We will not pursue legal action over good-faith research that respects user privacy and avoids service disruption.

security@karatrack.com