Security Overview
verified security practices and shared responsibilities for Pinsot
Introduction and scope
Pinsot is a product operated by Dakoli LLC, a California limited liability company. This document explains the rules, rights, procedures, and responsibilities that apply to verified security practices and shared responsibilities for pinsot
Pinsot provides subscription software and technology for nail salon operations in a global market. Salons are independent businesses that provide nail, beauty, wellness, and related services to their clients. Unless a document expressly says otherwise for a specific transaction, the salon—not Pinsot—is responsible for its services, prices, technicians, schedules, employment relationships, commissions, taxes, refunds, client care, licensing, sanitation, and regulatory compliance.
The English version is the controlling version unless applicable law requires otherwise. The Vietnamese translation is provided for meaningful access and convenience and is intended to preserve the same substance.
Accounts and access boundaries
Repository-verified controls include Better Auth-based account and session foundations, web HTTP-only session cookies, native secure storage through the supported Expo integration, server-side authorization, salon tenant isolation, location scope, role permissions, individual-user context, and session or device controls. Authentication alone does not grant salon or platform authorization.
Pinsot follows a least-privilege philosophy: a person should receive only the role, location, client, and workflow access needed for assigned work. Technician access is intentionally narrower than owner or authorized manager access. Customers are responsible for invitation review, role selection, prompt offboarding, device protection, and reporting suspected compromise.
Secure development and data minimization
The repository uses typed contracts, centralized permission checks, tenant-safety tests, input validation, sanitized errors, redacted diagnostics, code review, linting, type checking, focused automated tests, production builds, and release gates. High-risk workflows use server confirmation, explicit approval, immutable or append-only patterns where documented, and idempotency where needed to reduce duplicate effects.
Pinsot minimizes data exposed by role and prohibits credentials, full payment data, government identifiers, and other secrets in diagnostics. AI contracts include redaction, risk levels, source context, approval requirements, and bounded retry concepts. These controls reduce risk but do not guarantee that defects, misuse, or attacks cannot occur.
Infrastructure, logging, and continuity
Verified deployment records identify Vercel for public web delivery and Railway configuration for API and PostgreSQL environments. Logging, audit history, health checks, environment validation, secret separation, migration gates, and local backup and restore procedures exist in repository documentation. Public wording does not claim a specific encryption implementation, data region, uptime, recovery objective, certification, or production backup state until separately verified.
Customers should maintain independent records and continuity procedures for legally required accounting, payroll, tax, employment, licensing, sanitation, and regulatory information. An unavailable service, stale screen, or unknown provider result should cause users to stop repeated high-risk actions, preserve source records, check status, and escalate safely.
Incident response
Pinsot's incident approach is to identify affected scope, contain unsafe access or actions, preserve necessary evidence, assess data and operational impact, remediate the cause, restore service carefully, and provide notices required by contract or law. Response priority depends on safety, unauthorized access, data sensitivity, transaction impact, affected customers, and exploitability.
We do not publish operational details that materially increase attack risk. Customers should maintain current security contacts, cooperate with reasonable verification, preserve source records, avoid public speculation, and follow instructions for credential or device containment. Incident communications do not admit liability and may evolve as facts are verified.
Responsible disclosure
Use /security/report or email security@pinsot.com with a clear description, affected surface, safe reproduction steps, observed impact, and contact information. Remove live credentials and personal data. Do not access data that is not yours, degrade service, use social engineering, demand payment through threats, or publicly disclose an unresolved issue in a way that increases harm.
We will acknowledge a useful report, validate scope, prioritize by risk, communicate when practical, and coordinate remediation and disclosure. Submission does not guarantee a reward, safe-harbor protection beyond applicable law, or a particular timeline. Good-faith, proportionate research is considered differently from exploitation or extortion.
Changes, language, and contact
This document is version 2026.07.20, effective and last updated July 20, 2026. We may update it to reflect product, legal, safety, or operational changes. Material changes will be communicated through an appropriate public or in-product notice when reasonably required. Continued use after an effective change is governed by applicable law and any notice or consent that law requires.
Questions and requests concerning this document may be sent to security@pinsot.com. Contact addresses are centralized and require owner verification before production. Do not email passwords, verification codes, full payment credentials, government identification, health details, or unrelated client records.

