Back
Security Policy
Effective April 17, 2026
1. Our Commitment
We take the security of our customers' personal information seriously. This page describes the technical and organizational measures we use to protect your data, and how to responsibly report a security issue.
2. Technical Security Measures
Our application implements the following protections:
HTTPS / TLS encryption for all traffic, with HSTS preload (max-age 1 year, includeSubDomains)
Strict Content Security Policy (CSP) with default-src 'none' on API responses
Strict-Origin-When-Cross-Origin Referrer-Policy and noindex on admin paths
Permissions-Policy disabling camera, microphone, geolocation, payment, USB, and FLoC
Server-side input validation, length clamping, and HTML escaping on every form field
Honeypot field and submission-timing analysis to filter automated spam
Per-IP rate limiting (60 req/min general; 5 submissions per 10 min on forms; 10 admin login attempts per 15 min)
Progressive slow-down on repeated admin login attempts to deter brute-force
Body-size guard rejecting payloads over 16 KB before parsing (anti-zip-bomb)
Origin/Referer validation on sensitive endpoints as a CSRF backstop
CSRF tokens required for authenticated admin actions
Argon2id password hashing for admin credentials (memory-hard, modern KDF)
Postgres-backed sessions with httpOnly, secure, sameSite=lax cookies and 8-hour expiry
Re-authentication required for destructive admin actions (15-minute window)
Active blocklist of known scanner user-agents and exploit-probe paths
Slowloris protection via 30-second idle socket timeout
Daily outbound email quota cap to limit abuse blast-radius
No leaked stack traces or internal error details in API responses
Optional Cloudflare Turnstile bot verification (configurable via environment variable)
3. Data Practices
We do not collect payment card data — all financial transactions are handled outside the App
We do not collect or store Social Security numbers, government IDs, or precise device GPS
We do not use third-party advertising trackers, behavioral retargeting, or sell personal information
Booking inquiries are retained for up to 2 years for legitimate business records
Crash and error logs are retained for up to 90 days
4. Reporting a Vulnerability
If you believe you have discovered a security vulnerability in our website, mobile application, or API, please report it to us privately so we can investigate and remediate before public disclosure.
How to Report
Security Contact — Big Joe's Tacos & Catering
BigJoesTacos@Gmail.Com
Subject line: "Security Vulnerability Report"
A machine-readable contact is also published at /.well-known/security.txt in accordance with RFC 9116.
5. What to Include in Your Report
A clear description of the vulnerability and its potential impact
Step-by-step reproduction instructions (URLs, payloads, request/response samples)
The affected endpoint, page, or component
Your contact information for follow-up questions
Whether you would like public credit if the issue is confirmed
6. Our Commitments to Researchers
We will acknowledge receipt of your report within 5 business days
We will provide an initial assessment and triage within 10 business days
We will keep you informed of remediation progress
We will not pursue legal action against researchers who act in good faith and in accordance with this policy
We will offer public acknowledgment (where you wish to be named) on this page once issues are resolved
7. Safe-Harbor Scope & Rules
To stay within our safe harbor, please:
Test only against your own accounts and data — never use a third party's account without authorization
Do not perform automated denial-of-service, volumetric, or load testing
Do not attempt social engineering, phishing, or physical intrusion against our staff or vendors
Stop testing and report immediately if you encounter any personal data belonging to others
Do not publicly disclose the vulnerability until we have had a reasonable opportunity to fix it (typically 90 days)
Do not violate any applicable laws or regulations
Out-of-scope: third-party services we link to (Yelp, Facebook, Instagram, Google Maps), social engineering of staff, denial-of-service attacks, and reports based solely on missing best-practice headers without a demonstrable impact.
8. Acknowledgments
We thank the security community for helping keep our customers safe. Researchers who responsibly disclose verified issues will be acknowledged here (with their permission).