Security
Last updated: October 10, 2026
How to tell us about a security problem, and how TicketTuck protects the people who buy tickets and give through our pages.
Report a vulnerability
If you think you’ve found a security issue in TicketTuck, please tell us privately first.
Email security@tickettuck.com
Helpful things to include:
- what you found and why it matters;
- the address where it happens, and the steps to see it again;
- any screenshots or proof-of-concept code;
- how you’d like to be credited, if at all.
Please don’t put real card numbers or anyone else’s personal details in your report. We’ll confirm we’ve received it within 3 business days, keep you updated while we fix it, and let you know when it’s resolved. We ask that you give us 90 days to fix an issue before you talk about it publicly.
What’s in scope
- app.tickettuck.com: sign-in, the console, every organization’s studio and the event-day door app;
- Organization sites we serve: <name>.tickettuck.com, and organizations’ own web addresses that point to TicketTuck;
- tickettuck.com, our marketing site;
- the web APIs behind all of these.
Out of scope
- Services we use but don’t run, such as NMI (card fields and payments), Cloudflare and our email provider. Please report those to them directly.
- Denial-of-service or load testing, and anything that degrades the service for others.
- Phishing, social engineering or physical attacks on TicketTuck, organizations or their staff.
- Scanner output or missing best-practice headers without a demonstrated security impact.
- Issues that need an already compromised device or browser.
Ground rules
- Test only with accounts you created. Don’t access, change or delete anyone else’s data. If you come across personal data, stop and tell us.
- Never make purchases with real cards that aren’t yours, and never try card testing. Our pages take real payments.
- Don’t send spam or flood our forms or email.
Safe harbor
If you make a good-faith effort to follow this policy while researching TicketTuck, we will consider your research authorized. We will not pursue or support legal action against you for it, including under anti-hacking or anti-circumvention laws, and we will work with you to understand and fix the issue quickly. If a third party brings legal action against you for research done under this policy, we will make it known that your activity was authorized by us.
This safe harbor covers only TicketTuck’s own systems listed above. It doesn’t cover services run by others, and it can’t authorize access to an organization’s or a buyer’s data. If you’re unsure whether something is allowed, ask us at security@tickettuck.com before you go further.
How we protect card data
- Card numbers never reach TicketTuck. Buyers type their card details into fields hosted by NMI, our payment gateway. NMI hands back a one-time token, and that’s all our servers ever see. We don’t store card numbers, expiry dates or security codes; we keep only the card brand, the last four digits and the gateway’s transaction reference.
- Only approved code runs on payment pages. A strict Content Security Policy lets only our own code, NMI’s card fields and Cloudflare’s bot check run. Browsers report anything the policy blocks, and we check what our payment pages load every hour and review every change.
- Two-step sign-in. It’s required for TicketTuck’s own administrators and available to every user.
- Merchant keys are encrypted. Each organization’s payment gateway keys are encrypted at rest (AES-256-GCM) with a key held outside the database, and are never shown again once entered. Changing them requires the password and notifies the organization’s admins.
- Everything is over HTTPS, with strict transport security. Passwords are hashed, sessions are kept in secure cookies, and checkout is protected by a bot check and rate limits against card testing.
- Access is logged. Organizations can see who did what in their account, including when TicketTuck staff view their orders for support.
Contact
Questions about security, or a customer security review? Email security@tickettuck.com. Our security.txt file lists the same contact.