Buyer confidence
Condition first
Photos, flaws, pickup rules, and reserve status stay visible before bidding.
Customer-facing auction demo
A buyer can discover curated estate pieces, compare honest condition notes, set a private max bid, understand the total, and schedule pickup without guesswork.
Buyer confidence
Condition first
Photos, flaws, pickup rules, and reserve status stay visible before bidding.
Owner protection
Private minimum
The platform can show reserve status without exposing the owner minimum.
Pickup clarity
No guesswork
Winning buyers move from payment to appointment and release code.
What this experience proves
A simple customer path from item story to paid pickup, with seller protection built in.
01
Trust
Condition, reserve status, pickup terms, and payment safety are visible before commitment.
02
Bid
Private max bid behavior is demonstrated without exposing proxy values.
03
Pay
Buyer premium and total due are calculated before payment handoff.
04
Pickup
Paid lots move into appointment selection and release-code flow.
05
Sell
A buyer can become a consignment lead without leaving the experience.
Consumer demo
This path is built for a real customer conversation: clear lot facts, private max bidding, predictable totals, pickup scheduling, and a calmer way to ask about selling items.
Discover lots
Buyer confidence controls
Buyers need transparent condition reports, predictable payment handoff, accessible bidding, and clear pickup rules before they commit.
Stripe Checkout hosted redirect first; Stripe.js tokenized Elements only after additional review.
SAQ A-oriented posture, with eligibility confirmed by the acquiring bank, Stripe Dashboard, or QSA.
Custom card collection would expand PCI scope and add major annual audit burden.
Spam leads, credential stuffing, and automated bids can degrade trust quickly.
A buyer can miss bid status, fees, pickup rules, or form errors.
Leaking reserve or owner terms weakens negotiation leverage and owner trust.
Verified payment events
PCI DSS v4.0.1 / secure development
Implement Stripe webhook handler with signature verification before production checkout.
Session and CSRF controls
OWASP ASVS 5.0 aligned
Wire CSRF validation into every production state-changing route.
Hosted payment scope
PCI DSS v4.0.1 / SAQ A-oriented
Prefer Stripe Checkout redirect for MVP payment collection and retain the Stripe account attestation.