Customer-facing auction demo

Auction finds with the facts up front.

A buyer can discover curated estate pieces, compare honest condition notes, set a private max bid, understand the total, and schedule pickup without guesswork.

Buyer confidence

Condition first

Photos, flaws, pickup rules, and reserve status stay visible before bidding.

Owner protection

Private minimum

The platform can show reserve status without exposing the owner minimum.

Pickup clarity

No guesswork

Winning buyers move from payment to appointment and release code.

What this experience proves

A simple customer path from item story to paid pickup, with seller protection built in.

  1. 01

    Trust

    Condition, reserve status, pickup terms, and payment safety are visible before commitment.

  2. 02

    Bid

    Private max bid behavior is demonstrated without exposing proxy values.

  3. 03

    Pay

    Buyer premium and total due are calculated before payment handoff.

  4. 04

    Pickup

    Paid lots move into appointment selection and release-code flow.

  5. 05

    Sell

    A buyer can become a consignment lead without leaving the experience.

Consumer demo

A complete public flow for bidding, pickup, and consignment.

This path is built for a real customer conversation: clear lot facts, private max bidding, predictable totals, pickup scheduling, and a calmer way to ask about selling items.

View catalog

Discover lots

Browse with the facts a buyer needs.

Buyer confidence controls

Make the public auction feel polished, clear, and safer from the first bid.

Buyers need transparent condition reports, predictable payment handoff, accessible bidding, and clear pickup rules before they commit.

69readiness
Designed controls4
In progress5
Owner setup3

PCI scope posture

Stripe Checkout hosted redirect first; Stripe.js tokenized Elements only after additional review.

SAQ A-oriented posture, with eligibility confirmed by the acquiring bank, Stripe Dashboard, or QSA.

1/3

Payments

Custom card collection would expand PCI scope and add major annual audit burden.

0/3

Security

Spam leads, credential stuffing, and automated bids can degrade trust quickly.

0/1

Accessibility

A buyer can miss bid status, fees, pickup rules, or form errors.

1/2

Privacy

Leaking reserve or owner terms weakens negotiation leverage and owner trust.

Next compliance actions

Verified payment events

PCI DSS v4.0.1 / secure development

In progress

Implement Stripe webhook handler with signature verification before production checkout.

Session and CSRF controls

OWASP ASVS 5.0 aligned

In progress

Wire CSRF validation into every production state-changing route.

Hosted payment scope

PCI DSS v4.0.1 / SAQ A-oriented

Designed

Prefer Stripe Checkout redirect for MVP payment collection and retain the Stripe account attestation.

Allowed payment records

  • Stripe checkout session ID
  • Stripe payment intent or charge ID
  • non-sensitive card brand and last four digits when returned by Stripe

Never stored here

  • primary account number
  • CVV or sensitive authentication data
  • raw card form payloads