

Security & Data Protection
TiketCaribbean is committed to protecting your data with industry-leading security practices and standards. We continuously work towards achieving and maintaining recognised security certifications.
Issued by CaribraConnect Technology Ltd, trading as TiketCaribbean | Last updated: 13th March 2026
Our Security Commitment
We're dedicated to maintaining strong security standards to protect your personal information and your account. Our platform is built with security as a core principle, with multiple layers of protection from infrastructure through to application level.
Live security rating, independently verified:
Security Measures
Secure Technology Stack
Built with industry-leading technologies and security-first frameworks:
Infrastructure & Application Security
Hosted on Azure and Supabase cloud infrastructure
Built with C# .NET 8 backend architecture
Cloudflare protection for DDoS mitigation and bot filtering
Continuous dependency and vulnerability scanning with Snyk
Security-focused code reviews before every deployment
Data Protection & Encryption
AES-256 encryption for all data at rest (Supabase / Azure managed)
TLS 1.2/1.3 for all data in transit
BCrypt password hashing with industry-standard salting
HMAC-SHA256 JWT token signing (RSA migration prepared)
SHA-256 hashing for refresh tokens and OTP codes
HTTP-only cookies with SameSite and Secure flags
Access Control & Authentication
Role-based access control (RBAC) across all user types
OAuth 2.0 via Supabase (Google and Apple sign-in supported)
Sliding-session JWT management with secure token refresh
Rate limiting and automated lockout on repeated failed logins
Input sanitisation on all forms before API submission
Development Security Practices
OWASP Top 10 principles applied throughout development
All third-party dependencies audited before adoption
Sensitive credentials managed via environment variables only
No plaintext secrets committed to source control
Compliance Standards & Certifications
We are actively working towards achieving the following security certifications and compliance standards:
GDPR Compliance
General Data Protection Regulation for EU data privacy
Target Compliance
CCPA Compliance
California Consumer Privacy Act compliance
Target Compliance
SOC 2 Type 2
Information security policies and procedures framework (AICPA)
Planning
PCI DSS
Payment Card Industry Data Security Standard, to be met via certified payment processors
Planned
Payment Security
Ticket purchasing is not yet live on TiketCaribbean. When payments launch, we will integrate with PCI DSS-compliant payment processors, currently planned to include Stripe and Payoneer to best serve the Caribbean market. Our payment architecture is designed around these principles:
Card data will never be stored on TiketCaribbean servers
All payment data encrypted and tokenised by certified processors
PCI DSS compliance maintained via certified payment partners
Fraud detection and risk scoring handled at processor level
Continuous Security Improvement
Security is an ongoing commitment. As TiketCaribbean grows, we are continuously raising our security posture:
What we do today:
• Security-focused code reviews before every deployment
• Continuous vulnerability scanning with Snyk across code and dependencies
• Incident response process in place for security events
• OWASP Top 10 principles applied throughout active development
On our roadmap:
• Multi-factor authentication (MFA) for all accounts
• Single Sign-On (SSO) support for enterprise organisers
• Third-party penetration testing before payment launch
• Automated vulnerability scanning pipeline
• Bug bounty programme for responsible disclosure
• Backend migration to .NET 10
• SOC 2 and GDPR compliance audit once platform is fully live
Report a Security Issue
If you discover a security vulnerability or have security concerns, please report them to us immediately. We take all security reports seriously and will investigate promptly.
Contact Methods:
Security Email
security@tiketcaribbean.comGeneral Support
support@tiketcaribbean.comWhen Reporting:
• Provide detailed steps to reproduce the issue
• Include any relevant screenshots or logs
• Describe the potential impact of the vulnerability
• Do not publicly disclose the issue before resolution
Response Time:
We aim to respond to security reports within 24 hours and will keep you informed throughout the resolution process.