Skip to content

Security & privacy

Claims we can stand behind

This page reflects the product security model. We do not claim SOC 2 or other certifications we have not completed.

  • EU hosting preference

    Primary deployment target is Hetzner in the EU (Frankfurt) for data residency aligned with Magento merchants selling in Europe.

  • Tenant isolation by store_id

    Session tokens carry a verified store_id. Queries and chat history are scoped to that tenant — never taken from browser-supplied store identifiers alone.

  • No secrets in the widget

    The storefront only uses a public store key to start a session. JWT session tokens are issued after origin validation and captcha.

  • Encrypted Magento credentials

    OAuth / integration credentials are stored encrypted at rest. Secrets and OpenAI keys are never hardcoded or logged.

  • GDPR-minded chat data

    Visitor IPs are stored as SHA-256 hashes. Conversations support retention windows and deletion endpoints. Model calls receive question text — not unnecessary personal profiles.

  • Abuse controls

    Multi-layer rate limiting (IP, session, store) and CORS allow-lists for registered storefront origins.

Legal details: Privacy Policy, Cookie Policy, and Terms.

Next step

Questions about your data residency?

Request integration and we will review your Magento / Hyvä store. Or create an account first to track onboarding status.