Transparency & Trust

Our Commitment to Transparency

We believe that trust is earned through radical transparency. This page outlines our security posture, compliance goals, and public disclosures about how PickSafely operates.

Security Roadmap

We are committed to regular, independent security assessments to ensure our platform meets the highest standards.

Annual Third-Party Security Audit

To be conducted by an independent security firm - Q1 2026

Status
Planned
Details
A comprehensive review of our infrastructure, code, and security practices.
Report
Results will be published here upon completion.

Quarterly Penetration Testing

Internal and external testing - Ongoing

Status
In Progress
Details
We continuously test our systems for vulnerabilities to proactively address threats.
Report
Results will be published here upon completion.

Compliance Status

We are building our platform to align with international standards and regulations.

SOC 2 Type II

Planned for 2026

Verifies security, availability, and confidentiality controls.

Learn about SOC 2
GDPR

Self-Assessed

Adherence to EU data protection and privacy principles.

Read our Privacy Policy
CCPA

Self-Assessed

Adherence to California consumer privacy rights.

Read our Privacy Policy
PCI DSS

Compliant via Stripe

Payment data is secured via our partner, Stripe.

Learn about Stripe Security

Public Disclosures

In the interest of transparency, we publicly disclose key information about our operations.

Data Handling Practices

  • All participant email addresses are encrypted using AES-256 encryption at rest.
  • We use SHA-256 cryptographic hashing for winner selection.
  • Personal data is automatically deleted 90 days after account closure.
  • Giveaway verification pages remain public permanently for transparency.
  • We never sell or share participant data with third parties.

Infrastructure & Uptime

Status provided by third-party monitoring. (e.g. UptimeRobot, Checkly)

Current Uptime
99.9%+
Last 90 days
Response Time
~150ms
Average globally
Data Centers
5
Across 3 continents

Incident History

DateTypeImpactDuration
No security or data incidents reported to date.

Questions About Our Practices?

Enterprise customers can request custom security assessments and due diligence documentation.