Skip to content
security & quality

Built to be trusted with your business.

How we protect your data, your customers and your site, in plain words. Everything here is in use on our own platform today. Where we hold no certificate, we say so.

Default denyAccess control
SHA-256Every plugin update verified
GDPRConsent, export, erasure built in
EUCompany, team and contracts
01

In the platform

Access is locked by default

Every screen and every connection starts closed. People see exactly what their role allows and nothing more.

Logins are protected

Login sessions are handled on the server, and admin and customer logins are kept separate.

Updates are verified before they run

Every add-on and design package is checked against its fingerprint before it runs. Anything that doesn't match is refused.

Add-ons can't reach your core data

An add-on only sees its own data. Your users, roles and settings are reached through protected channels, never directly.

Protected against abuse

Checkout, forms and login are protected against automated abuse, and our own services authenticate to each other before they talk.

Backups and restores are buttons

Backups run from your admin and restore to the point you choose. Your content keeps versions you can compare and roll back.

02

In how we work

Tested before release

Automated tests cover the parts where a mistake costs money or exposes data, and each release is checked by hand before it goes out.

Checked in the browser

A feature is finished when it has been seen working on a phone and a desktop, doing what it says. Passing tests alone aren't enough.

No secrets in code

Passwords and keys are never written into code. Our repositories are scanned for them automatically.

Payments and stock stay correct under load

Stock, balances and commissions can't be double-counted, and every payout is previewed before a cent moves.

03

Your data, your terms

GDPR by design

Consent, data export and deletion requests are built in, at no extra cost. Cookie consent declines by default.

Hosting you choose

Run it with us, in your own cloud account, or on your own hardware. Nothing depends on our servers.

You own the source

Code written for you is yours, handed over in full. If you leave, there's nothing to untangle first.

Report a vulnerability

Write to [email protected]. We acknowledge within two working days and credit reporters who want it.

certifications

What we don't claim

We don't hold ISO 27001 or SOC 2 today, and we won't show a badge we haven't earned. If your procurement needs one, tell us; we'll walk your security team through everything on this page.

Tell us what you want to build or improve.

A few lines are enough to start. You get a reply within two working days.

Discuss your project