Skip to main content

    Security & Data Protection

    TiketCaribbean is committed to protecting your data with industry-leading security practices and standards. We continuously work towards achieving and maintaining recognised security certifications.

    Issued by CaribraConnect Technology Ltd, trading as TiketCaribbean | Last updated: 13th March 2026

    Our Security Commitment

    We're dedicated to maintaining strong security standards to protect your personal information and your account. Our platform is built with security as a core principle, with multiple layers of protection from infrastructure through to application level.

    Live security rating, independently verified:

    Security Measures

    Secure Technology Stack

    Built with industry-leading technologies and security-first frameworks:

    Infrastructure & Application Security

    • Hosted on Azure and Supabase cloud infrastructure

    • Built with C# .NET 8 backend architecture

    • Cloudflare protection for DDoS mitigation and bot filtering

    • Continuous dependency and vulnerability scanning with Snyk

    • Security-focused code reviews before every deployment

    Data Protection & Encryption

    • AES-256 encryption for all data at rest (Supabase / Azure managed)

    • TLS 1.2/1.3 for all data in transit

    • BCrypt password hashing with industry-standard salting

    • HMAC-SHA256 JWT token signing (RSA migration prepared)

    • SHA-256 hashing for refresh tokens and OTP codes

    • HTTP-only cookies with SameSite and Secure flags

    Access Control & Authentication

    • Role-based access control (RBAC) across all user types

    • OAuth 2.0 via Supabase (Google and Apple sign-in supported)

    • Sliding-session JWT management with secure token refresh

    • Rate limiting and automated lockout on repeated failed logins

    • Input sanitisation on all forms before API submission

    Development Security Practices

    • OWASP Top 10 principles applied throughout development

    • All third-party dependencies audited before adoption

    • Sensitive credentials managed via environment variables only

    • No plaintext secrets committed to source control

    Compliance Standards & Certifications

    We are actively working towards achieving the following security certifications and compliance standards:

    GDPR Compliance

    General Data Protection Regulation for EU data privacy

    Target Compliance

    CCPA Compliance

    California Consumer Privacy Act compliance

    Target Compliance

    SOC 2 Type 2

    Information security policies and procedures framework (AICPA)

    Planning

    PCI DSS

    Payment Card Industry Data Security Standard, to be met via certified payment processors

    Planned

    Payment Security

    Ticket purchasing is not yet live on TiketCaribbean. When payments launch, we will integrate with PCI DSS-compliant payment processors, currently planned to include Stripe and Payoneer to best serve the Caribbean market. Our payment architecture is designed around these principles:

    Card data will never be stored on TiketCaribbean servers

    All payment data encrypted and tokenised by certified processors

    PCI DSS compliance maintained via certified payment partners

    Fraud detection and risk scoring handled at processor level

    Continuous Security Improvement

    Security is an ongoing commitment. As TiketCaribbean grows, we are continuously raising our security posture:

    What we do today:

    • • Security-focused code reviews before every deployment

    • • Continuous vulnerability scanning with Snyk across code and dependencies

    • • Incident response process in place for security events

    • • OWASP Top 10 principles applied throughout active development

    On our roadmap:

    • • Multi-factor authentication (MFA) for all accounts

    • • Single Sign-On (SSO) support for enterprise organisers

    • • Third-party penetration testing before payment launch

    • • Automated vulnerability scanning pipeline

    • • Bug bounty programme for responsible disclosure

    • • Backend migration to .NET 10

    • • SOC 2 and GDPR compliance audit once platform is fully live

    Report a Security Issue

    If you discover a security vulnerability or have security concerns, please report them to us immediately. We take all security reports seriously and will investigate promptly.

    Contact Methods:

    When Reporting:

    • • Provide detailed steps to reproduce the issue

    • • Include any relevant screenshots or logs

    • • Describe the potential impact of the vulnerability

    • • Do not publicly disclose the issue before resolution

    Response Time:

    We aim to respond to security reports within 24 hours and will keep you informed throughout the resolution process.

    Questions About Our Security?

    If you have questions about our security practices, data protection measures, or compliance status, our team is here to provide information and address your concerns.