Account protection
Passwords are hashed, sign-in endpoints are throttled, inactive accounts are blocked, and session tokens can be revoked on logout.
Trust Center
This page describes implemented platform controls without claiming certifications, audits, or compliance programs that are not evidenced in the product.
Passwords are hashed, sign-in endpoints are throttled, inactive accounts are blocked, and session tokens can be revoked on logout.
Checkout uses local/mock or configured provider lifecycles. Webhooks support signature verification when provider secrets are configured privately.
Digital products are delivered only after paid-order entitlement checks through short-lived signed links and private storage metadata.
Payout queues show lifecycle, risk level, and redacted account labels. Account numbers, tax IDs, and provider credentials are not exposed by APIs.
Marketplace, storefront, status, and mobile public responses avoid private emails, mobile numbers, admin notes, secret values, webhook payloads, and private file paths.
Admin changes to users, products, settings, providers, payouts, search rules, support, SEO, notifications, and content are audit logged with sensitive metadata redacted.
Public-safe status
Public status is limited while admin monitoring remains internal.
Private incidents, stack traces, provider payloads, customer PII, private revenue, and secrets are not shown on public status pages.
What not to share in support