Security and retention
Last reviewed: 17 September 2026
- HTTPS is mandatory for public traffic; production customer records are stored on an encrypted volume.
- Encrypted daily backups are retained for 30 days and restore checks are recorded.
- Production and test datasets are separate. Production secrets and files use least-privilege permissions.
- Production access is restricted to authorised operators using strong authentication; direct SSH password login is disabled.
- Authenticated reads and downloads of customer documents and privacy exports are recorded without copying customer content into the log.
- Data minimisation, PII scrubbing, expiry jobs and Shopify redaction webhooks form the data-loss-prevention strategy.
- A documented incident process covers containment, evidence preservation, impact assessment, notification and recovery.
See the privacy policy for the detailed retention schedule.