Encryption
- AES-256 encryption for all data at rest
- TLS 1.3 for all data in transit
- Encryption keys are rotated regularly and stored separately from the data they protect
- Database backups are encrypted using the same standards as production data
Infrastructure
- Hosted on Vercel (edge network) and Supabase (managed Postgres)
- Both infrastructure providers are SOC 2 Type II compliant
- Automatic failover and redundancy across multiple availability zones
- Regular automated backups with tested restore procedures
Access Control
- Role-based access control (RBAC) across all internal systems
- Two-factor authentication (2FA) available and encouraged for all accounts
- Principle of least privilege applied to all internal service accounts
- All production access is logged and reviewed on a regular basis
Data Handling
- Fully GDPR compliant — see our GDPR page for details
- Your data is never sold to or shared with third parties for marketing purposes
- Data Processing Agreements (DPAs) available for enterprise customers
- Customer data is logically isolated between merchant accounts
Embed Security
- The StreamCart embed script is loaded asynchronously and never blocks page rendering
- No persistent cookies are set on your store visitors' browsers
- All API endpoints used by the embed are CORS-restricted to your verified domain
- Content Security Policy (CSP) compatible — the embed can be whitelisted with a single directive
Vulnerability Disclosure
- We operate a responsible disclosure program for security researchers
- To report a vulnerability, email security@streamcart.it with a description and reproduction steps
- We commit to acknowledging all valid reports within 48 hours and providing a resolution timeline within 7 days
- We do not take legal action against researchers who responsibly disclose vulnerabilities to us
Questions about security?
Whether you're a security researcher, an enterprise customer evaluating our controls, or just want to know more about how we protect your data, we're happy to talk.
security@streamcart.it