Security and data
Your data, in its own database, leaving only when you send it.
Almost every large customer runs a security assessment before they sign, and the person running it does not want marketing copy. This page is the list, with a status on every row, in the honest verbs we use everywhere else.
Controller and processor
The partner running the store is the data controller. We are the processor.
Every tenant has its own database, storage bucket, DNS zone and certificate. Data leaves a tenant only through the connectors that tenant enables in the Integration Hub, and the data processing addendum sets out the roles.
What ships, and what does not
Every control, with its status.
Every store its own catalog, pricing, customers, theme, cache keys, domains and certificates — with surgical per-tenant purge. Not rows in a shared table.
In-house TOTP, encrypted secrets, backup codes, step-up on sensitive actions across all three admin surfaces.
Your issuer, your claims, mapped to store accounts. Customer social login alongside it.
Automatic verification and renewal; canonical and robots handling across the custom domain and the subdomain.
Provider credentials scoped per tenant and encrypted at rest; CORS management; a system log; a partner API with webhook delivery, retry and an audit log.
An append-only event log with daily rollups; raw events pruned at 90 days.
A verified 12-domain gap audit with findings mapped across all five Trust Services Criteria. A readiness programme is underway. Brandfora is not SOC 2 certified.
Send us the questionnaire.
We answer it in the same verbs as this page. What we do not hold, we say we do not hold.