Trust Center

Security you can
actually verify.

Every photo, design, and payment on Custom Case Kiosk is protected by strong, modern controls. This page lays out exactly how — and how to reach the security team directly.

Last updated August 2026

TLS 1.3 in transitPCI DSS Level 1 paymentsAES-256-GCM at restContent screening that fails safe

Security controls

The measures in place today across the platform. Filter by area.

Encryption & transport
Encryption in transit
In place
Customer uploads, designs, and orders travel over TLS 1.3, the current standard. Older, weaker protocol versions are refused.
HTTPS everywhere
In place
Every page and request is served over HTTPS and protected by HTTP Strict Transport Security, so connections can't be silently downgraded.
Hardened security headers
In place
Every page ships a complete set of security response headers that block clickjacking, content-type confusion, and unnecessary data leakage.
Encryption at rest
In place
Sensitive contact details are encrypted at rest with AES-256-GCM.
Payments
PCI DSS Level 1 processing
In place
Card payments are handled entirely by a PCI DSS Level 1 certified processor — the highest tier. Custom Case Kiosk never receives or stores full card numbers.
Tamper-proof pricing
In place
Order totals are calculated and verified server-side. Prices cannot be altered from the browser.
Verified payment confirmations
In place
Payment confirmations are cryptographically signature-verified and protected against replay before an order is ever marked paid.
Platform & content safety
Automated content moderation
In place
Every design is automatically screened for prohibited content before it's printed. Anything that violates the content policy is blocked, and the check fails safe.
No cross-customer access
In place
Orders and records are protected by hard-to-guess identifiers and strict, fail-closed access controls. One customer can never reach another's data.
Data & privacy
Data minimization
In place
Only the data needed to fulfill an order is kept. Full card data is never stored, and payment records retain only a non-identifying financial summary.
Limited retention
In place
Moderation records automatically expire after 90 days, and customer images are kept only for a limited period.
Audit logging
In place
Privileged actions are recorded in an audit trail tied to a named account.
Access & engineering
Secure development lifecycle
In place
Every change goes through version control, mandatory peer review, and automated security and quality checks before it ships. Each deployment traces back to a reviewed change.
Least-privilege access
In place
Team access to systems and data is role-based and limited to what each role needs, with unique, named accounts.

Who’s in the data path

The categories of service providers in the platform’s data path.

Payment processing

Square · PCI DSS Level 1

Captures and processes card payments; full card data never reaches Custom Case Kiosk.

Cloud infrastructure & hosting

Enterprise cloud providers

Run the application, storage, and databases on audited, enterprise-grade infrastructure.

Content moderation

Automated image screening

Screens uploaded designs for prohibited content before printing.

Messaging

Email & SMS delivery

Send order confirmations and receipts. Used only to communicate with customers about their orders.

Contact the security team

Security questions and vulnerability reports go straight to the Custom Case Kiosk security team.