Skip to content
Fehrist

Fehrist security

Trust is a system, not a badge.

Security is built across account access, tenant boundaries, checkout integrations, infrastructure and incident response. We describe current controls without claiming certifications we have not earned.

Control 01

Encryption

HTTPS protects data in transit. Sensitive platform secrets and gateway credentials are handled through dedicated protected storage and are not exposed in storefront code.

Control 02

Tenant isolation

Authorization is scoped to the merchant and store so one tenant cannot legitimately read or change another tenant's records.

Control 03

Access control

Role-based staff permissions, account verification and security logging reduce unnecessary administrative access.

Control 04

Payment boundaries

Supported gateways process payment credentials through their own secure flows. Fehrist stores provider references needed to operate orders and refunds.

Control 05

Application security

Input validation, rate limiting, audit records, dependency checks and security headers form layers around the public and authenticated surfaces.

Control 06

Continuity

Backups, health monitoring and incident response procedures are designed to support recovery and responsible notification.

Shared responsibility

Fehrist secures the platform. Merchants secure how they use it.

Use unique staff accounts, minimum necessary permissions, secure recovery methods and careful app approvals. Keep exported customer data protected, review unexpected logins and remove staff access promptly when a role changes.

Responsible disclosure

Found a security issue?

Report it privately with the affected URL, impact, reproduction steps and proof that avoids accessing unnecessary data. Do not disrupt services, use social engineering, retain customer data or publicly disclose an unresolved issue.

security@fehrist.com

Privacy and processor commitments are documented separately.