Security

What is actually implemented in the code.

Every item on this page corresponds to a line of running code. We name no certification and no external audit while there is no publishable evidence for one.

PASSWORDS

Passwords are not stored

They are kept as PBKDF2-HMAC-SHA256 with 200,000 iterations and a per-account random salt, compared in constant time. A password cannot be recovered from the database — not by us, and not by anyone who reaches it.

CREDENTIALS

Your store credentials are encrypted

WooCommerce, Shopify and YouCan keys and your WhatsApp token are stored Fernet-encrypted. If the encryption key is missing the system refuses to save rather than writing them in the clear.

SESSIONS

A session token is never stored as issued

Only its hash is kept, and a session expires after 30 days. A sign-in code lives 10 minutes, capped at 3 requests and 5 verification attempts.

DATABASE

No query is built from text

Every read and write goes through bound parameters; no statement is assembled by string concatenation. That closes SQL injection at the source rather than by filtering.

WEBHOOKS

Every inbound event is signature-checked

Meta callbacks are verified against an HMAC-SHA256 signature, and if the secret is not configured the request is refused rather than accepted. Transport is HTTPS with a one-year HSTS policy.

ISOLATION

One merchant's data stays theirs

Every route checks record ownership before returning it, and an automated test prevents one shop's conversation reaching another when both share a WhatsApp number.

BACKUPS

Nightly backups, encrypted to a public key

A daily copy, kept 14 days. The private key needed to decrypt it is never on the server — compromising the server reaches the live data, not the archive.

ERASURE

The right to erasure is built, not promised

You can action a customer's erasure request from the dashboard: name, phone, address and message text are removed, while orders and amounts remain because your accounting must. Each erasure is written to a log that stays your evidence.

ACCESS

And a copy of the data on request

A full JSON export of everything held about one customer, for the right of access and portability.

What we do not claim

Customer details — name, phone, address — are stored in the database without field-level encryption; what is encrypted is connection credentials. We do not enforce a TLS version from inside the application; that sits at the server layer. Rate limiting applies to the sign-in code only. We say so because a security page that hides its limits is not one.