01
Encryption
Public endpoints run TLS. Secrets and tokens are hashed or encrypted at rest where the infrastructure supports it.
Secure Core
In every module
Written first
The bar, on paper
PDPL ready
Engineering. Not a certificate
Risk reduced
Never gone. You hold your keys
Secure Core
The same four controls Shieldra writes into government and private systems. Designed in from the first module. Not bolted on after launch.
01
Public endpoints run TLS. Secrets and tokens are hashed or encrypted at rest where the infrastructure supports it.
02
Roles separate owners, finance, and frontline staff. Production access is need-to-know, and it is logged.
03
Sensitive changes leave a trail. Kayan actions that move money appear in an action log you can read.
04
Each workspace is logically isolated. Catalog, conversations, orders, wallet, and integrations stay scoped to your tenant.
In this product
The house standard, written into the commerce workspace. No invented stamp. What is in the product is what we state here.
Cross-tenant access is blocked at the application and database layers. Your books stay in your tenant.
Refunds, payouts, and spend can require approval and a cap. Those actions are logged. Undo exists where the product supports it.
Connected platforms follow their rules, including Meta data-deletion. You can disconnect a channel and remove what came with it.
The bar, written
Shieldra code of business. We do not sell a stamp we do not hold. Security reduces risk. It does not eliminate it.
This page summarises measures. It does not replace your review, a questionnaire, or a formal audit.
PDPL readiness is engineering against Law 151 of 2020. It is not a PDPC certificate. GDPR for the German house is the legal situation, not a stamp.
Do not probe the live system without written permission. Unsolicited penetration tests are not supported.
Your side
We cannot protect a shared password or an unused integration you left connected.
Strong passwords. Least privilege. Review who is in the workspace.
Set the tools, the hours, and the stop. Review spend caps before Kayan can move money.
Your devices and your training stay with you. Disconnect what you no longer use.
Report
security@sastemny.com
Suspected vulnerability or account compromise. Include steps to reproduce and what is at risk. We investigate by severity.
FAQ
No public SOC 2 or ISO stamp is claimed here. PDPL readiness is engineering, not a certificate.
No. Security reduces risk. It does not eliminate it. You still protect credentials and devices.
No. Isolation is logical and scoped by tenant. Cross-tenant access is blocked in the application and the database.
Not without a written agreement. Write to security@sastemny.com first.
security@sastemny.com. Steps to reproduce and impact. We investigate by severity.
Create a workspace, or send the request. Security reports go to security@sastemny.com.