Platform Security & Data Protection at DealDone

Security is engineered directly into every layer of DealDone. We prioritize data minimization, cryptographic standards, hardened infrastructure, and rapid incident response to safeguard our users' personal information and messaging communications.

Encryption in Transit & at Rest

All communication between client applications (Web, Android, iOS) and DealDone server infrastructure is strictly enforced over HTTPS utilizing TLS 1.3 protocol suites with Perfect Forward Secrecy (PFS). Real-time chat messages and offer updates are transmitted across secure WebSockets (WSS). Sensitive database records are encrypted at rest using industry-standard AES-256 encryption.

Authentication & Session Integrity

Account credentials are protected using salted, computationally hardened hashing algorithms (Argon2 / PBKDF2). DealDone sessions use short-lived, cryptographically signed JSON Web Tokens (JWT) stored in secure, HttpOnly, SameSite cookies to protect against Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vectors. Multi-factor authentication via SMS OTP is enforced during sensitive account actions.

Zero Payment Card Storage

Because DealDone operates as a peer-to-peer cash and swap marketplace where members complete transactions face-to-face, DealDone does not collect, process, or store credit card numbers, CVV codes, or bank account credentials on our database servers. This architecture eliminates the primary vulnerability targeted in e-commerce data breaches.

Automated Threat & Spam Detection

Our infrastructure includes real-time rate limiting, IP reputation filtering, automated honeypot defenses, and heuristic content filtering to detect and ban automated scraping bots, mass spam generators, and brute-force credential stuffing attempts before they reach legitimate users.

Responsible Disclosure Program

We welcome collaboration with cybersecurity researchers. If you identify a potential security vulnerability within any DealDone application or API endpoint, please notify us immediately at security@dealdone.club. We commit to acknowledging receipt within 24 hours, evaluating the issue promptly, and working collaboratively with researchers without legal action under our safe harbor policy.

Frequently Asked Questions

How does DealDone protect user data?
DealDone enforces modern TLS 1.3 encryption in transit, salted Argon2 password hashing at rest, hardened API token sessions, and strict database access controls.
Does DealDone store financial credit card details?
No. DealDone does not process or store sensitive payment card information on our servers. Local transactions are conducted directly peer-to-peer.
How do I report a security vulnerability?
Security researchers can report findings directly to security@dealdone.club under our Responsible Disclosure Policy.