Security

Last updated

Tenant isolation

Shop data is stored in a shared Postgres schema with a tenant id on each tenant-owned row. PostgreSQL row-level security ties queries to the current shop session so one merchant's orders and customers are not returned to another.

Merchant login users are global (one person can belong to several shops). Authorisation happens through memberships and roles inside each shop.

Encrypted connections

Production traffic to the apps and API is served over HTTPS. Use a current browser and do not bypass certificate warnings.

Hashed passwords

Account passwords are hashed with argon2id before storage. We do not store plaintext passwords. Session refresh tokens are stored as hashes as well.

Roles and audit log

Staff access is role-based with permissions checked on API routes. Sensitive actions and denied authorisation attempts can be written to an append-only audit log that shop staff with audit permission can review.

Backups

Primary data is planned on managed Cloud SQL, which provides provider-managed database backups. We do not claim a separate custom backup product beyond that managed service.

Responsible disclosure

If you find a security issue, email security@ecomprops.com with enough detail to reproduce it. Please do not access other merchants' data or disrupt the service while testing.

We will acknowledge reports when we can and prioritise fixes that protect customer data.

Security · ecomprops