Security
Last updated: 16 August 2026
PlateAPI is built and operated by WolfStack Solutions (ABN 26 877 229 839). This page outlines the measures we use to protect your account and data.
Infrastructure
- All data is stored on dedicated servers in Sydney, Australia
- No data is stored or replicated outside Australia
- Internal services are not directly accessible from the internet
- DDoS protection and bot management via Cloudflare
- Intrusion detection on all server access
- Least-privilege database access controls
Encryption
- All connections use HTTPS with TLS 1.2 or higher
- HSTS enforced with preload
- Sensitive data encrypted at rest using AES-256-GCM
- Passwords hashed with argon2id and a server-side pepper
Authentication
- Short-lived session tokens with automatic rotation
- Cookies are httpOnly, Secure, and SameSite -- not accessible to JavaScript
- Optional TOTP two-factor authentication (Google Authenticator, Authy, etc.)
- CSRF protection on all state-changing requests
Abuse Prevention
- Rate limiting on login, registration, and API requests
- Automatic account lockout after repeated failed logins
- All authentication events logged for audit
- Per-plan API rate limits enforced server-side
API Keys
- Generated using cryptographically secure randomness
- Rotatable from the dashboard at any time
- Rotation immediately invalidates the previous key
- 2FA required for key rotation when enabled
Security Headers
- Strict-Transport-Security (HSTS)
- Content-Security-Policy
- X-Content-Type-Options
- X-Frame-Options
- Referrer-Policy
- Permissions-Policy
- Server version information suppressed
Payments
- All payment processing handled by Stripe (PCI DSS Level 1)
- We never see or store credit card numbers or bank details
- Payment pages are served directly by Stripe
Cookies
- Essential cookies for authentication and session management
- Google Ads conversion tracking cookies to measure ad performance
- No third-party analytics cookies (Plausible and Cloudflare Web Analytics are cookieless)
Data Retention
- API usage logs retained for 12 months, then deleted
- Account data deleted within 30 days of account closure
- Financial records retained as required by Australian tax law
Incident Response
In the event of a data breach, we will notify affected users by email within 72 hours and report qualifying breaches to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
Vulnerability Reporting
If you discover a security vulnerability, please email [email protected] with "SECURITY" in the subject line. We ask that you allow reasonable time for us to address the issue before public disclosure. Our security contact is also published at /.well-known/security.txt.
Questions
For questions about our security practices, contact us at [email protected].