Security
Version 3.4 · effective April 27, 2026
This page describes the security measures of Shopxare, LLC. It is the summary referred to in our Terms of Service and Annex II of our Data Processing Addendum.
1. Infrastructure
- The Services run on servers in a data center in Türkiye, operated by Veriup Bulut İnternet Hizmetleri A.Ş.
- Traffic passes through Cloudflare, which provides DNS, TLS, protection against denial-of-service attacks and a web application firewall.
- Server firewalls only allow the ports the Services need. Real-time and call relay services run on separate, restricted ports.
- Operating system security updates are applied regularly.
2. Data protection
- In transit: all connections to shopxare.com, app.shopxare.com, the Messenger, the apps and the API use TLS 1.2 or newer. Calls relayed by our servers can use TLS as well.
- Secrets: integration tokens, API keys of AI providers, Telegram bot tokens and similar credentials are stored encrypted. API tokens and passwords are stored only as hashes.
- Tenant isolation: every Workspace's data is separated in the application; every query is limited to the Workspace of the signed-in user, and this is covered by automated tests.
- Backups: the database and stored files are backed up every day and kept for 35 days, with access restricted to authorised personnel.
3. Accounts and access
- Passwords are hashed with a modern, salted algorithm and must have at least 10 characters with letters and numbers.
- Two-step verification with an authenticator app is available to every teammate.
- Sign-in protection: unusual sign-ins (for example from a new browser or country) and sensitive actions ask for an extra confirmation — an email code, an authenticator code, or an approval in the Shopxare mobile app.
- Roles and permissions decide what each teammate can see and do; custom roles are available.
- Audit log: important actions in a Workspace are recorded with the person, time and IP address.
- Shopxare staff access customer Workspaces only to provide support you request, to investigate abuse or as the law requires. Such access is logged.
4. Application security
- Protection against common web attacks: CSRF tokens, output escaping, strict Content Security Policy and other security headers, and validation of all input on the server.
- Rate limits on sign-in, forms, the Messenger and the API.
- Messenger identity verification: your server signs your users' IDs with an HMAC, so nobody can impersonate them.
- Webhooks are signed (HMAC-SHA256 with a timestamp) and only sent to public addresses.
- Uploads are checked for type and size and served from a separate path with safe headers.
- Automated tests run before every release.
5. Monitoring and availability
- The Services are monitored every minute; results are published on our status page.
- Errors are logged with a reference number so we can trace problems quickly.
6. Incident response
We have a documented process to detect, contain, investigate and recover from security incidents. If an incident affects your personal data, we notify you without undue delay and within 72 hours, as set out in our DPA.
7. Your part
Security is shared. Turn on two-step verification, give teammates only the roles they need, enable identity verification for the Messenger if your users sign in, keep API tokens secret and revoke the ones you no longer use.
8. Reporting a vulnerability
Please follow our Responsible Disclosure Policy or use the vulnerability report form.