Security at Fillpics

At Fillpics, safeguarding your data and ensuring reliable service is our top priority. We follow strict protocols, use industry-leading technology, and continuously monitor our systems to deliver a secure and seamless experience for all our clients and event participants.

Team & Access Control

All contractors and collaborators working with Fillpics are required to sign confidentiality agreements before accessing any part of our infrastructure or codebase. While we do not conduct background checks, we maintain a rigorous hiring process that includes multi-step evaluations such as portfolio reviews, coding challenges, and interviews to ensure only trusted professionals handle sensitive areas of our platform.

System Access

Our platform is built on Google Cloud infrastructure, using Firebase as our backend-as-a-service. We do not manage our own servers, which allows us to leverage Google Cloud’s advanced security. Access to Firebase and other sensitive dashboards is secured by two-factor authentication (2FA), with all security management handled under Google Cloud’s enterprise-grade protections.

Development & Quality Assurance

To ensure the reliability of our service, our engineering team follows strict development practices. This includes automated testing (unit, integration, and code analysis) combined with manual checks in a staging environment. Updates and improvements are released regularly, usually on a weekly deployment cycle, ensuring Fillpics remains stable, secure, and up-to-date.

Encryption Standards

All data transmitted through Fillpics is protected using 256-bit Secure Socket Layer (SSL) encryption along with the SHA-256 with RSA algorithm. Our SSL configuration scores A+ on SSL Labs quality reports.

Stored data on Google Cloud is protected with default encryption at rest, using either AES-256 or AES-128. You can learn more about Google Cloud’s encryption methods here: Google Cloud Security.

Password Security

User passwords are securely hashed and stored using bcrypt, a proven and trusted cryptographic hashing algorithm provided by Google Cloud.

Payment Security

All financial transactions on Fillpics are handled by a PCI-DSS compliant third-party provider (such as Paddle). We do not store or process any payment details directly on our servers. Once a subscription is canceled, all related payment information is automatically deleted by our payment processor. More details can be found here: Paddle Compliance.

Infrastructure & Backup Policy

Data Centers

Fillpics is hosted on Firebase, part of Google Cloud Platform, with data stored across the EU Central (Spain/Germany) and US Central regions depending on client location. Google Cloud is one of the most secure hosting platforms globally, certified with ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, and CSA.

Physical Security

Google Cloud data centers are equipped with multi-layered physical security measures, including electronic access cards, alarms, biometric scanners, vehicle barriers, and 24/7 monitoring to prevent unauthorized entry.

Backups

We perform daily encrypted backups of all critical data. Backups are stored securely and automatically removed after 30 days, ensuring both recovery capability and compliance with data retention best practices.

Service Reliability & Continuity

High Availability

Fillpics relies heavily on Firebase services hosted on Google Cloud, which guarantees excellent uptime and reliability. You can view the live status of Firebase services here: Firebase Status Dashboard.

Threat Prevention & Mitigation
  • Authentication Security: We use Firebase authentication monitoring to block suspicious IPs or repeated attack attempts.
  • App Validation: Fillpics integrates Firebase App Check with reCAPTCHA v3 to prevent fraudulent requests and intrusion attempts.
  • Cloudflare Protection: To enhance security and performance, we utilize Cloudflare, which filters malicious traffic, mitigates DDoS attacks, and optimizes content delivery for smooth user experiences.

Incident Response

If you discover any vulnerability, bug, or abuse within the Fillpics platform, please report it immediately to admin@fillpics.com. In the rare event of a security incident, we will notify all affected clients promptly and work transparently with you until the issue is resolved.

Business Continuity

To guarantee uninterrupted service, Fillpics maintains daily encrypted backups on Firebase. In the unlikely event of production data loss, these backups allow us to restore services quickly and securely.