Security
This page summarizes Ricazza's public security posture at a high level. It intentionally avoids sensitive technical details.
Account and access controls
Ricazza uses account authentication, role-based access, and server-side checks for protected seller, agent, agency, admin, favorite, contact, listing, and billing actions.
- Published listings are public; drafts, private contact fields, profile-review requests, leads, billing state, and admin workflows are restricted.
- Seller and agent tools check ownership or assigned role before sensitive operations.
- Sensitive changes are verified on the server instead of relying only on browser state.
Data protection
Ricazza uses HTTPS, access controls, validation, abuse prevention, restricted private data access, and public-data minimization to reduce exposed data and platform risk.
- Search results and public pages are designed to expose public listing information, not private contact, verification, billing, or draft-only data.
- Contact, listing-view, favorite, listing mutation, billing, verification, and import surfaces use backend validation and rate or abuse controls where implemented.
- Security headers, media validation, logging, and audit trails are part of the operating model.
Reporting security issues
Report suspected vulnerabilities to security@ricazza.com. Include affected URL, steps to reproduce, impact, and any safe proof of concept. Do not access, modify, delete, exfiltrate, or disclose other users' data; do not disrupt service; do not run destructive, high-volume, social-engineering, phishing, spam, or physical attacks.
No guarantee
No internet service can guarantee perfect security. Ricazza may update controls, rotate credentials, limit accounts, remove content, preserve logs, or notify users and authorities when required by law or when needed to protect the platform.