Trust
Data security & device sanitisation
Two kinds of data are at stake: what's on your device, and what you tell us about yourself. Here is how each is protected.
The data on your device
Every device we buy is sanitised before it leaves our hands, following NIST Special Publication 800-88 Rev. 1, the U.S. standard for media sanitisation:
- Clear — factory reset plus cryptographic erase for devices with hardware encryption (all modern iPhones, Pixels, Galaxy and Macs, Windows laptops with BitLocker/TPM).
- Purge — ATA/NVMe secure-erase for bare drives and older laptops, verified by read-back.
- Destroy — storage is physically shredded when a device cannot be powered on or a purge cannot be verified. Non-functional devices go to an R2/e-Stewards certified recycler only after their storage is removed and destroyed.
We record the method, date and technician for every device and you can download a Certificate of Data Sanitisation from your account. Our staff do not browse, copy or retain your files; a device that arrives with data on it is treated as abandoned property and sanitised.
What you should do before shipping: back up; sign out of iCloud/Google/Microsoft accounts; turn off Find My, Activation Lock and Factory Reset Protection; remove SIM and SD cards; factory reset if the device still boots. Devices with an active activation lock cannot be resold and will be revised or returned.
Your personal information
- Encryption in transit — TLS 1.2+ on every page, HSTS enforced.
- Encryption at rest — government ID numbers are encrypted with AES-256-GCM. The key is stored outside the web root, not in the database. Only the last four digits are ever displayed by default; each full reveal by staff is written to an audit log.
- Least data — we never store bank account, card or routing numbers. Bank details go directly to Stripe. IP addresses are stored only as salted SHA-256 hashes.
- Access control — separate admin roles, inactivity time-outs, CSRF protection, rate-limited logins, bcrypt password hashing, optional Google sign-in.
- Private storage — inspection photos and documents live outside the web root and are served only to the seller and staff after authentication.
- Hardened delivery — Content-Security-Policy with per-request nonces, X-Frame-Options, no third-party scripts until you consent.
- Automatic deletion — unaccepted quotes after 90 days, ID numbers 3 years after your last sale, everything else when you delete your account (except the 7-year transaction ledger required by law, which is pseudonymised).
Reporting a vulnerability
If you find a security issue, email support@doctorpcb.com. We will acknowledge within 2 business days and will not pursue good-faith researchers.
If something goes wrong
We follow Idaho Code §28-51-105 and GDPR Art. 33–34: affected people are notified without unreasonable delay, and regulators where required.