Built to be trusted with your business.
How we protect your data, your customers and your site, in plain words. Everything here is in use on our own platform today. Where we hold no certificate, we say so.
In the platform
Access is locked by default
Every screen and every connection starts closed. People see exactly what their role allows and nothing more.
Logins are protected
Login sessions are handled on the server, and admin and customer logins are kept separate.
Updates are verified before they run
Every add-on and design package is checked against its fingerprint before it runs. Anything that doesn't match is refused.
Add-ons can't reach your core data
An add-on only sees its own data. Your users, roles and settings are reached through protected channels, never directly.
Protected against abuse
Checkout, forms and login are protected against automated abuse, and our own services authenticate to each other before they talk.
Backups and restores are buttons
Backups run from your admin and restore to the point you choose. Your content keeps versions you can compare and roll back.
In how we work
Tested before release
Automated tests cover the parts where a mistake costs money or exposes data, and each release is checked by hand before it goes out.
Checked in the browser
A feature is finished when it has been seen working on a phone and a desktop, doing what it says. Passing tests alone aren't enough.
No secrets in code
Passwords and keys are never written into code. Our repositories are scanned for them automatically.
Payments and stock stay correct under load
Stock, balances and commissions can't be double-counted, and every payout is previewed before a cent moves.
Your data, your terms
GDPR by design
Consent, data export and deletion requests are built in, at no extra cost. Cookie consent declines by default.
Hosting you choose
Run it with us, in your own cloud account, or on your own hardware. Nothing depends on our servers.
You own the source
Code written for you is yours, handed over in full. If you leave, there's nothing to untangle first.
Report a vulnerability
Write to [email protected]. We acknowledge within two working days and credit reporters who want it.
What we don't claim
We don't hold ISO 27001 or SOC 2 today, and we won't show a badge we haven't earned. If your procurement needs one, tell us; we'll walk your security team through everything on this page.
Tell us what you want to build or improve.
A few lines are enough to start. You get a reply within two working days.
