Control 01
Encryption
HTTPS protects data in transit. Sensitive platform secrets and gateway credentials are handled through dedicated protected storage and are not exposed in storefront code.
Control 01
HTTPS protects data in transit. Sensitive platform secrets and gateway credentials are handled through dedicated protected storage and are not exposed in storefront code.
Control 02
Authorization is scoped to the merchant and store so one tenant cannot legitimately read or change another tenant's records.
Control 03
Role-based staff permissions, account verification and security logging reduce unnecessary administrative access.
Control 04
Supported gateways process payment credentials through their own secure flows. Fehrist stores provider references needed to operate orders and refunds.
Control 05
Input validation, rate limiting, audit records, dependency checks and security headers form layers around the public and authenticated surfaces.
Control 06
Backups, health monitoring and incident response procedures are designed to support recovery and responsible notification.
Shared responsibility
Use unique staff accounts, minimum necessary permissions, secure recovery methods and careful app approvals. Keep exported customer data protected, review unexpected logins and remove staff access promptly when a role changes.
Responsible disclosure
Report it privately with the affected URL, impact, reproduction steps and proof that avoids accessing unnecessary data. Do not disrupt services, use social engineering, retain customer data or publicly disclose an unresolved issue.
security@fehrist.comPrivacy and processor commitments are documented separately.