Security & privacy
Claims we can stand behind
This page reflects the product security model. We do not claim SOC 2 or other certifications we have not completed. We do not name a hosting region or provider as a current fact.
Tenant isolation by store_id
Session tokens carry a verified store_id. Queries and chat history are scoped to that tenant — never taken from browser-supplied store identifiers alone.
No secrets in the widget
The storefront only uses a public store key to start a session. Session tokens are issued after origin validation. OpenAI keys never ship in the browser.
Encrypted Magento credentials
OAuth / integration credentials are stored encrypted at rest. Secrets and OpenAI keys are never hardcoded or logged.
Retention intent
Visitor IPs are stored as hashes. Conversations support retention windows (default target: 90 days) and deletion endpoints. Model calls receive question text — not unnecessary personal profiles.
No SOC 2 in v1
We do not claim SOC 2 or ISO certification. We publish isolation, encryption, and retention — not a certificate wall.
Abuse controls
Multi-layer rate limiting (IP, session, store) and CORS allow-lists for registered storefront origins.
How isolation applies to Magento chat: AI chatbot for Magento 2 and Hyvä. Legal details: Privacy Policy, Cookie Policy, and Terms.
Next step
Questions about isolation or retention?
Request integration and we will review your Magento / Hyvä store. We invoice after fit — no payment on the form.