PASSWORDS
Passwords are not stored
They are kept as PBKDF2-HMAC-SHA256 with 200,000 iterations and a per-account random salt, compared in constant time. A password cannot be recovered from the database — not by us, and not by anyone who reaches it.
Security
Every item on this page corresponds to a line of running code. We name no certification and no external audit while there is no publishable evidence for one.
PASSWORDS
They are kept as PBKDF2-HMAC-SHA256 with 200,000 iterations and a per-account random salt, compared in constant time. A password cannot be recovered from the database — not by us, and not by anyone who reaches it.
CREDENTIALS
WooCommerce, Shopify and YouCan keys and your WhatsApp token are stored Fernet-encrypted. If the encryption key is missing the system refuses to save rather than writing them in the clear.
SESSIONS
Only its hash is kept, and a session expires after 30 days. A sign-in code lives 10 minutes, capped at 3 requests and 5 verification attempts.
DATABASE
Every read and write goes through bound parameters; no statement is assembled by string concatenation. That closes SQL injection at the source rather than by filtering.
WEBHOOKS
Meta callbacks are verified against an HMAC-SHA256 signature, and if the secret is not configured the request is refused rather than accepted. Transport is HTTPS with a one-year HSTS policy.
ISOLATION
Every route checks record ownership before returning it, and an automated test prevents one shop's conversation reaching another when both share a WhatsApp number.
BACKUPS
A daily copy, kept 14 days. The private key needed to decrypt it is never on the server — compromising the server reaches the live data, not the archive.
ERASURE
You can action a customer's erasure request from the dashboard: name, phone, address and message text are removed, while orders and amounts remain because your accounting must. Each erasure is written to a log that stays your evidence.
ACCESS
A full JSON export of everything held about one customer, for the right of access and portability.
Customer details — name, phone, address — are stored in the database without field-level encryption; what is encrypted is connection credentials. We do not enforce a TLS version from inside the application; that sits at the server layer. Rate limiting applies to the sign-in code only. We say so because a security page that hides its limits is not one.