Book a demo

Security and data

Your data, in its own database, leaving only when you send it.

Almost every large customer runs a security assessment before they sign, and the person running it does not want marketing copy. This page is the list, with a status on every row, in the honest verbs we use everywhere else.

Controller and processor

The partner running the store is the data controller. We are the processor.

Every tenant has its own database, storage bucket, DNS zone and certificate. Data leaves a tenant only through the connectors that tenant enables in the Integration Hub, and the data processing addendum sets out the roles.

What ships, and what does not

Every control, with its status.

Per-tenant isolation RUNNING

Every store its own catalog, pricing, customers, theme, cache keys, domains and certificates — with surgical per-tenant purge. Not rows in a shared table.

MFA on admin surfaces RUNNING

In-house TOTP, encrypted secrets, backup codes, step-up on sensitive actions across all three admin surfaces.

Per-store OIDC SSO RUNNING

Your issuer, your claims, mapped to store accounts. Customer social login alongside it.

Custom domains with managed TLS RUNNING

Automatic verification and renewal; canonical and robots handling across the custom domain and the subdomain.

Integration Hub credentials RUNNING

Provider credentials scoped per tenant and encrypted at rest; CORS management; a system log; a partner API with webhook delivery, retry and an audit log.

Append-only analytics RUNNING

An append-only event log with daily rollups; raw events pruned at 90 days.

SOC 2 BRINGING ON

A verified 12-domain gap audit with findings mapped across all five Trust Services Criteria. A readiness programme is underway. Brandfora is not SOC 2 certified.

Send us the questionnaire.

We answer it in the same verbs as this page. What we do not hold, we say we do not hold.