Last Updated on August 30, 2026 by Mat Diekhake

Security Overview

Curtsy is a U.S. peer‑to‑peer fashion resale marketplace operating on a modern SaaS infrastructure with strong HTTPS enforcement, reputable cloud hosting, and clean malware‑scan results. External technical‑security checks show no indicators of compromise, and its architecture aligns with expectations for a mobile‑first resale platform.

SSL/TLS & Encryption

Curtsy enforces HTTPS across its entire platform and uses a valid TLS certificate issued by Amazon Trust Services. External scans indicate:

  • Modern TLS configuration
  • No mixed‑content issues
  • No weak‑cipher warnings
  • Proper certificate chain and renewal behavior

All user–server communication is encrypted.

Hosting & Infrastructure

Detected infrastructure includes:

  • Amazon Web Services (AWS) hosting
  • Cloudflare CDN and reverse‑proxy protection
  • Additional supply‑chain services such as Google Tag Manager, Google Analytics, Stripe, Amplitude, Zendesk, and other marketplace‑standard tooling
  • Infrastructure consistent with a mobile‑centric U.S. resale marketplace

Domain founded: March 25, 2016

No uptime‑instability warnings or infrastructure‑risk flags were reported in external scans.

Malware & Phishing Scan

Automated security checks show:

  • No detected malware
  • No phishing blacklist flags
  • No suspicious redirects
  • No unauthorized third‑party script injections

Curtsy’s technical footprint appears clean and free of malicious behavior.

Privacy & Data Handling

Curtsy processes:

  • Account information
  • Listing and transaction data
  • Payment‑related metadata (via secure processors)
  • Device and usage analytics

Tracking technologies include:

  • Google Tag Manager
  • Google Analytics
  • Amplitude
  • Facebook Pixel
  • Standard cookie‑consent mechanisms

Policies indicate standard marketplace privacy practices. No excessive tracking behaviors were detected.

App Permissions (If Applicable)

The Curtsy mobile app typically requests:

  • Notification access
  • Optional camera/file access for listing photos
  • Optional location access for shipping and pickup‑related features

These permissions match expected functionality for a fashion resale marketplace.

Breach History

Publicly available security intelligence shows no disclosed major data breaches involving Curtsy. No leaked databases, credential‑stuffing exposures, or public security incidents have been reported.

Security Certifications

Curtsy’s published security posture and vendor‑risk listings indicate alignment with:

  • GDPR
  • PCI DSS (payment‑related)
  • Standard marketplace security controls

Formal SOC 2 or ISO 27001 certifications are not publicly listed.

Final Safety Verdict

Curtsy is technically safe to use. It employs strong HTTPS/TLS encryption, uses reputable cloud and CDN providers, and shows no malware or phishing detections in external scans. Its infrastructure and privacy posture align with modern marketplace security expectations, and no breach history has been reported.

Website: curtsyapp.com