Security
The safeguards that protect your data and your customers’ data
Tenant isolation, encryption, authentication, separation of duties, an audit log and a safe payment flow are part of the product's foundations. This page describes the controls that are in place; it is not a certification or an uptime commitment.
What is in place?
Tenant isolation
Each store's data is separated from the others with PostgreSQL row-level security (RLS). When no store context is set, no rows are visible. A user who is not a member of a store cannot even learn that it exists.
Authentication
Passwords are stored with Argon2id; sessions and tokens are kept as hashes. Cookies are HttpOnly, Secure and __Host- prefixed, and requests need a CSRF token and an origin check. Repeated failed sign-ins are stopped by a temporary lock.
Two-factor sign-in and confirmation codes
Two-factor sign-in with time-based one-time codes (TOTP), which the store owner can make mandatory for all staff. Sensitive actions such as deleting a store, transferring ownership and creating an API key that can change data are confirmed with a one-time code sent by e-mail.
Encryption
Public traffic is carried over TLS, with certificates issued and renewed automatically. Payment keys, module settings, webhook secrets, two-factor secrets and identity numbers are stored encrypted with AES-256-GCM.
Card numbers never rest on the platform
Card details are entered on the payment pages hosted by iyzico, PayTR or Stripe; the platform never sees the full card number. Notifications from the provider are verified by signature, and the amount and order status are queried again from the provider.
Payment methodsRoles and permissions
Ready-made system roles (owner, admin, manager, editor, support) and custom roles, view and edit permissions for each area and limits by sales channel. API keys only work with the scopes they are given.
Audit log and alerts
Who changed what and when is kept in the audit log with IP and device details, with sensitive fields masked. An e-mail alert goes out on a sign-in from an unrecognised device, when a password changes and when two-factor sign-in is reset.
Outbound requests and storefront security
Outbound requests such as webhooks, imports and image URLs are blocked from reaching private network addresses (SSRF protection). The storefront applies a nonce-based content security policy to each request, and extra scripts do not run without a cookie consent category.
Backups, access logs and abuse reports
Under the operating procedure, backups are encrypted, kept off the server and verified by test restores. Access logs (including the source port) are kept in line with Law 5651, and abuse reports have their own form and handling process.
Team and permissions
Give your team only the access it needs
Invite staff by e-mail and assign one of the ready-made roles or a role you create yourself. Each area has its own view and edit permission, and access can be limited by sales channel.
You can make two-factor sign-in mandatory for all staff and, when needed, give the platform support team time-limited access and take it back. The number of staff depends on your plan.
- Ready-made roles and custom roles
- Permissions per area and sales channel
- Mandatory two-factor sign-in for all staff
- Time-limited support access: grant and revoke

Domain and SSL
Your own domain with automatic SSL
When you add a domain, the panel shows which DNS records to enter. The domain is verified with a TXT record that proves you own it, so nobody can attach someone else's domain to their store. For a verified domain the SSL certificate is issued and renewed automatically.
You pick the primary domain and redirect the other addresses to it with a 301; you can switch HSTS, which tells browsers to use HTTPS, on or off per domain.
- Ownership verification with a TXT record
- Automatic certificate issuing and renewal
- A primary domain and 301 redirects
- HSTS per domain
Did you find a vulnerability?
If you find a vulnerability, please tell us before sharing it anywhere public. Send the report through the contact page, starting your message with “Security report”, and include the affected component, the steps and the likely impact.
Please do not access other users' data, run tests that could disrupt the service, or attempt social engineering or physical tests. Our aim is to acknowledge your report and to make a coordinated disclosure once a fix is in place; we do not intend to take legal action against researchers who report in good faith.
This page is not a certification, an independent audit report or a service-level commitment; it describes the controls applied in the product.
Frequently asked questions
Are card details stored on your servers?
No. Card details are entered on the payment page hosted by iyzico, PayTR or Stripe; the platform neither sees nor stores the full card number. See payment methods for details.
Can I make two-factor sign-in mandatory for my staff?
Yes. In the security settings you can make two-factor sign-in mandatory for all staff; once it is mandatory, staff who have not set it up cannot act in the store until they do, and the panel shows you which staff members have not.
What should I do if my API key leaks?
Revoke the key in the panel; revocation takes effect immediately. Then review the key's use in the audit log and create a new one if needed. Because a key only works with the scopes it was given, the impact is limited to those permissions.
Can I export my data?
You can export your orders and customers from the panel as CSV; the product CSV and other bulk operations are a plan feature. There is also a panel flow for customers who ask for their own data (KVKK requests: export and anonymisation).
Do you hold a security certification such as ISO 27001?
We make no certification claims on this page; what we describe are controls applied in the product's code. If your procurement process needs more information, write to us.
Start with a store that is built to be safe
Open your account, invite your team and turn on two-factor sign-in from day one. No credit card is asked during the trial.