Tap4Go · Bimbiamore LLC
Security & Trust
Tap4Go uses layered application and hosting controls. This page is a transparent security overview, not a certification or an absolute guarantee.
Application controls
- TLS/HTTPS for data in transit and encrypted SMTP transport.
- Passwords stored only as adaptive bcrypt hashes; reset/verification tokens and selected contact/legal IP values stored as one-way hashes or pseudonymised values.
- Session cookies configured as HttpOnly, SameSite=Lax, Secure on HTTPS and session-lifetime; session IDs rotate after authentication.
- CSRF tokens, prepared database statements, input validation, HTML sanitisation and strict URL/iframe allowlists.
- Rate limits for authentication, registration, recovery, activation, leads and analytics ingestion.
- Role-based administration and permissions; audit records for privileged project actions.
- Uploaded images are MIME/size/dimension validated, decoded and re-encoded, which strips most embedded metadata.
- First-party interaction events are written only to daily aggregate counters without a visitor identifier. Google Analytics is disabled until analytics consent; external YouTube media is blocked until media consent.
Hosting and resilience
Tap4Go is hosted by Hostinger. Hostinger’s current DPA describes physical access controls, role-based access, strong authentication, encryption of communications and data at rest, vulnerability scans, penetration testing for critical platforms, monitoring, incident response, backups, redundancy and DDoS protection. These are Hostinger’s representations and certifications do not automatically certify Bimbiamore LLC. Review the Hostinger Trust Center and Hostinger DPA.
Encryption clarification
Traffic is encrypted in transit and Hostinger represents infrastructure/data-at-rest encryption. Passwords are hashed, not encrypted, so they cannot be decrypted by Tap4Go. Tokens and selected IP-derived identifiers are one-way hashed. Operational profile, lead and page data must remain readable to authorised application processes to deliver the Service; we do not claim that every individual database field is application-level encrypted.
Shared responsibility
Customers must protect credentials, limit administrators, verify public content, avoid unnecessary sensitive data, remove obsolete data and notify us quickly of compromise. Public profile data is intentionally public and cannot be made confidential through platform security.
Vulnerability and incident contact
Report a suspected Tap4Go vulnerability or incident privately to info@tap4go.com with steps to reproduce and no unnecessary personal data. Do not access, alter, exfiltrate or publicly disclose other users’ data, disrupt service, use social engineering or demand payment. We will acknowledge good-faith reports and coordinate remediation. Hostinger infrastructure issues may also be reported under its Responsible Disclosure Policy.