Legal
Security Overview
High-level description of how MyTravelPeace protects the service and data.
- Version
- 2.0.0
- Effective Date
- August 7, 2026
- Last Updated
- August 7, 2026
Introduction
This Security Overview describes, at a high level, how MyTravelPeace approaches protection of the Service. It is a public summary, not a warranty and not a certification report.
Additional detail appears in the Privacy Policy. Operational Admin monitoring is internal and not a customer security console.
Authentication
Customer Accounts authenticate through our identity provider (Supabase Auth). Password handling follows the provider’s practices; MyTravelPeace application databases are not designed to store plaintext passwords.
The Admin Platform requires a separate active internal-administrator membership and is not granted by ordinary customer signup.
Account Protection
You are responsible for protecting your credentials and for activity under your Account. Use a strong unique password and notify us if you suspect unauthorized access.
We may restrict access when we detect abuse, failed authorization attempts, or other security risk signals recorded in operational logs.
General Security Practices
Practices appropriate to a SaaS application include encrypted transport (HTTPS) for the Service, authenticated access controls, separation of customer and Admin roles, and privacy-conscious operational logging (including hashing of IP addresses for certain security events where implemented).
Operational Monitoring
Authorized administrators may review security, activity, and system monitoring signals to operate and protect the Service. Public Radar aggregate counters support operational visibility without storing prompt transcripts as the aggregate design.
Responsible Access
Internal operators are expected to use Admin access only for legitimate operational purposes. Customer-facing policy text remains published under /legal; Admin Legal monitoring of acceptances is a future phase.
Third-Party Infrastructure
Hosting, authentication, database, payments, and AI inference rely on subprocessors listed on the Subprocessors page. Their security programs apply to the services they provide.
Incident Response Philosophy
Pending Legal ReviewIf a security incident affecting Personal Information occurs, we aim to investigate promptly, contain impact where practicable, and notify affected individuals or authorities when required by law.
- Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
- Formal notification timelines and templates will be confirmed by counsel.
No Unsubstantiated Certifications
Unless we separately publish a current independent attestation, you should not assume SOC 2, ISO 27001, government certifications, or completed penetration-test reports based on this Overview alone.
Contact
Pending Legal ReviewQuestions about this document may be directed to MyTravelPeace through the support channel designated by the operator.
Pending Legal Review — this section requires counsel confirmation for jurisdiction-specific wording.
Related documents: Privacy Policy, Terms of Service, and other pages linked from the Service footer.
Revision History
| Version | Date | Notes |
|---|---|---|
| 2.0.0 | August 7, 2026 | LGL-3 Security Overview without unsubstantiated certifications. |
| 1.0.0 | August 7, 2026 | LGL-1 architecture baseline. |