Security & Data Protection.
BreakersDNA is a transparency platform: break results are public by design, and your business data is private by design. Here is exactly how we protect both — no marketing gloss, every claim checked against how the platform is actually built.
Where the Money Lives
Payments are usually the first question, so let's answer it precisely.
- •Buyer money never touches BreakersDNA— spots, cards, and auctions are bought and paid for on the selling platform you already use (Whatnot, eBay Live, Fanatics Live). We never see, hold, or process a buyer's payment details.
- •Subscriptions are the only payments we process — companies on paid BreakersDNA plans pay through Stripe-hosted checkout and billing pages. Card numbers go directly to Stripe and never touch our servers or our database; we store plan status and invoice records, never card data.
- •Payment events are verified and processed once — every billing notification from Stripe is signature-checked before we act on it, and duplicate deliveries are ignored.
- •No surprise bills — plan caps throttle usage instead of generating overage invoices, and every refund is recorded in an audit trail.
What to Check for Your Role
Different people come to this page with different worries. The short answers:
If you're a buyer
- You never pay BreakersDNA, and we never see how you paid your breaker — purchases stay on the marketplace where you bought (Whatnot, eBay Live, Fanatics Live).
- Break results are sealed and publicly verifiable — receipts and break pages show the seal with a Verify link, and the verification page recomputes the fingerprint live.
- Your email and shipping address are never public. You control your public profile, and you can export or delete your data from settings.
If you're a breaker
- Your costs, margins, manifests, and buyer lists are isolated to your workspace at the database layer — no other company can query them, and cost basis never appears on a public page.
- Sealed results protect you from “they edited it later” — completed breaks reject changes, and reopening one visibly revokes its seal.
- Every staff override — like a manual price correction — leaves an audit trail with who, what, and when.
If you're a repacker
- Certification proves your manifest without revealing it — the public certificate page verifies the content fingerprint live and never shows raw contents, costs, or estimated values.
- Anyone holding a certificate number can check it — edits after certification show up as a fingerprint mismatch.
- Your sourcing and cost data sit behind the same workspace isolation as every other company's.
If you're a platform
- We're the transparency layer, not a competing marketplace — checkout, payments, and shipping stay on your platform.
- Public break pages carry only public-by-design facts; buyer personal data and breaker economics never cross that boundary.
- Evaluating us for a partnership? Contact us and we'll work through your security questionnaire.
If you're a manufacturer
- Catalog data is compiled from official product information with per-field source attribution — every value traces back to where it came from.
- Corrections run through audited admin tooling, so changes to your product data leave a trail.
Tamper-Evident Results
Trusting break results shouldn't require trusting us. Completed results are fingerprinted so anyone can check them.
- •Every completed break is sealed — a SHA-256 fingerprint is computed over the physical results (cards pulled, spots, settled sale prices) and issued with a seal number shown on public receipts and break pages.
- •Anyone can verify a seal — the public verification page recomputes the fingerprint from the current data on every visit; if anything changed after sealing, the mismatch is visible.
- •Sealed breaks reject edits — the API refuses changes to a completed break. Reopening a break revokes its seal on the public record, and re-completing issues a new one.
- •Fingerprints cover facts, not estimates— seals are computed from physical results and settled prices, never from fluctuating market estimates, so price movement can't fake or break a seal.
- •Certified repack manifests work the same way — a content fingerprint verifiable by anyone holding the certificate number, without exposing the manifest itself.
Encryption & Infrastructure
- •Encrypted in transit — all traffic is served over TLS
- •Encrypted at rest — databases and file storage use AES-256 encryption
- •Credentials stored as hashes — passwords, API keys, and tokens are never stored in plaintext
- •Two-factor authentication — link an authenticator app from your account settings. Once enrolled, the code is required on every sign-in and enforced by the server, not just the login screen, so a stolen password on its own is not enough to reach your data. Single-use recovery codes cover a lost device.
- •Private storage with expiring links — media buckets block all public access, upload URLs expire within minutes, and staging uploads are deleted automatically on a schedule
Access Control
- •Workspace isolation enforced at the database — hundreds of row-level security policies scope every private record to the company that owns it
- •Sensitive columns are gated too — even on tables that power public pages, private fields like cost basis and internal valuations are blocked from public database roles at the column level
- •Fail closed— if your identity can't be confirmed, the request is rejected rather than allowed through
- •Permission-bound roles — scanner, operator, company-admin, and platform roles each see only what their job requires
- •Rate limiting on sensitive endpoints like signup, password reset, and contact forms
Audit & Monitoring
- •Audit logs — security-relevant actions are recorded with who, what, when, IP, and outcome
- •Administrative actions leave a trail— manual price overrides, refunds, and privacy changes are all audited, and internal access grants are append-only records that can't be silently erased
- •Continuous error monitoring — with credentials, cookies, and sensitive parameters stripped before anything leaves our systems
Public by Design, Private by Design
Transparency is the product. Break results, receipts, channel pages, and directory listings are public so buyers can verify what happened. Privacy controls cover the rest:
- •Public — completed break pages, per-spot receipts (sale price, card, platform username), channel history, and directory listings
- •Never public — emails, passwords, shipping addresses, cost basis, and margins
- •Your controls — buyers control their public profile and can have their public history hidden on request; companies can request removal from public directories
Your Data, Your Controls
- •Your data is never sold
- •No sharing for third-party advertising — data goes only to the service providers that run the platform (hosting, email delivery, AI card identification, error monitoring)
- •AI is for card identification— card images and card text go to recognition providers to identify cards; we don't use your personal information to train AI models of our own
- •Export or delete it yourself — download a copy of your personal data or delete your account directly from settings, no support ticket required
The full details — every category of data, every processor, every opt-out — are in our Privacy Policy. Evaluating BreakersDNA for your company and need a security questionnaire completed? Contact us.