NudgeWin

Security

NudgeWin uses layered application, transport and platform controls to protect accounts and service data while keeping the product practical for small service businesses.

Transport and browser protections

Production traffic is served over HTTPS. NudgeWin also sends security headers including HSTS, Content Security Policy, frame restrictions, MIME-sniffing protection, a referrer policy and a restrictive browser permissions policy.

Accounts and billing

Account authentication is handled by NudgeWin's established authentication layer. Subscription checkout and billing management are handled through Stripe, so NudgeWin does not collect raw card details in its own application forms.

Analytics and privacy

Product analytics are configured to avoid credentials, payment data, customer contact details, quote contents and quote amounts. Session recording is disabled, and analytics failures are isolated from core product workflows.

Operational safeguards

Webhook-driven billing and email events are validated before state changes are applied, and duplicate billing events are handled idempotently. Production health checks monitor application and database availability.

Report a security concern

Please report suspected security issues privately to supportnudgewin@gmail.com. Include enough detail to reproduce the issue, but do not send passwords, API keys, payment details or other secrets.