Security & privacy
Claims we can stand behind
This page reflects the product security model. We do not claim SOC 2 or other certifications we have not completed.
EU hosting preference
Primary deployment target is Hetzner in the EU (Frankfurt) for data residency aligned with Magento merchants selling in Europe.
Tenant isolation by store_id
Session tokens carry a verified store_id. Queries and chat history are scoped to that tenant — never taken from browser-supplied store identifiers alone.
No secrets in the widget
The storefront only uses a public store key to start a session. JWT session tokens are issued after origin validation and captcha.
Encrypted Magento credentials
OAuth / integration credentials are stored encrypted at rest. Secrets and OpenAI keys are never hardcoded or logged.
GDPR-minded chat data
Visitor IPs are stored as SHA-256 hashes. Conversations support retention windows and deletion endpoints. Model calls receive question text — not unnecessary personal profiles.
Abuse controls
Multi-layer rate limiting (IP, session, store) and CORS allow-lists for registered storefront origins.
Legal details: Privacy Policy, Cookie Policy, and Terms.
Next step
Questions about your data residency?
Request integration and we will review your Magento / Hyvä store. Or create an account first to track onboarding status.