Security
Last updated September 5, 2026.
We build and run our own infrastructure, so security is our own responsibility rather than a vendor's. This page describes what we actually do.
Data in transit and at rest
Every website and API we operate is served over HTTPS with modern TLS, and HTTP requests are redirected. Mail is sent over TLS wherever the receiving server offers it. Passwords are stored as salted hashes and are never recoverable, by us or anyone else.
Payments
Card details are collected and stored by Stripe, a PCI-DSS Level 1 provider, on their own hosted checkout. Full card numbers never reach our servers or our database. We receive only the card brand, last four digits, country and the result of the charge.
Payment forms are protected by per-IP and per-account rate limits and a decline ledger that blocks repeated failed attempts, which is how automated card testing is stopped before it becomes a pattern.
Access control
Administrative access to production systems is limited to the people who operate them, over key-based SSH only, from restricted networks. Customer data is not copied to personal machines. Application secrets are held in server-side configuration that is never committed to source control.
Infrastructure
We operate our own servers in datacenters in the United States and Asia, behind firewalls, with automatic TLS certificate renewal and monitored service health. Databases run in replica sets so a single machine failure does not lose data, and backups are taken regularly.
Reporting a vulnerability
If you find a security problem in any of our products, email support@rnsagency.com with the details and we will respond within 1 business day. Please give us a reasonable chance to fix it before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith and does not access other people's data.
RNS STAR LLC · 99 Wall Street #112, New York, United States 10005 · support@rnsagency.com · +1 878 867 9832