Trust
Security Overview
MyPass applies layered controls designed to protect business accounts, attendee information, and access-validation operations. Security is a shared responsibility between Lepews LLC, Clients, authorized users, and service providers.
Platform safeguards
- Encrypted HTTPS connections for supported production web traffic.
- Authenticated administrative access and permission controls within the platform.
- Limited collection of payment details: MyPass retains transaction references and display information rather than full card credentials.
- Security maintenance and access restrictions designed to reduce unauthorized use.
Payment security
When payment processing is enabled, payment credentials are collected through Stripe-hosted or Stripe-provided payment components. MyPass does not store full payment-card numbers or card security codes. Payment status and limited references may be retained for billing, reconciliation, and support.
Client responsibilities
Clients should use unique credentials, restrict administrative permissions, protect validation devices, review authorized users, and remove access promptly when a person no longer needs it. Credentials must not be shared through insecure channels.
Security incidents
Lepews investigates suspected security incidents and notifies affected Clients as required by contract and applicable law. Clients must promptly report suspected account compromise, unexpected pass activity, unauthorized disclosure, or other security concerns.
Responsible reporting
Send security reports to [email protected] with enough detail to reproduce and assess the issue. Do not access, alter, retain, or disclose data that does not belong to you, disrupt the Service, use automated destructive testing, or publicly disclose an unresolved issue.
No absolute guarantee
No online service can guarantee complete security. This overview describes current practices at a high level and does not create a warranty or expand commitments stated in a signed Client agreement.