Skip to content
StoreFlux
Features Developers Security Pricing Docs FAQ
Sign in Start free
Features Developers Security Pricing Docs FAQ
Start free Sign in
Home/Legal/Security & Disclosure

Security & Responsible Disclosure

How StoreFlux protects your store and your customers’ data, and how to report a vulnerability to us safely.

Last updated: October 3, 2026 Applies to storeflux.store, the admin panel and the API
On this page
  1. How we protect the platform
  2. Reporting a vulnerability
  3. What to expect from us
  4. Safe harbor
  5. Out of scope
  6. Incident response

Security is a core part of how StoreFlux is built, not an add-on. This page summarises the mechanisms that protect the platform and sets out how researchers can report problems to us. For the marketing overview see the security section of our homepage.

01How we protect the platform

AreaWhat we do
Tenant isolationPostgreSQL row-level security enforces tenant boundaries at the database layer, in addition to application-level checks, so a query for one store cannot return another store’s rows.
SecretsPayment-gateway keys and integration OAuth tokens are encrypted at rest with a dedicated secret protector and are never stored or logged as plain text.
PaymentsCard data is tokenised client-side by Stripe Elements or the PayPal SDK and never touches StoreFlux servers. Payment and refund operations use distributed locks and gateway idempotency keys to prevent double charges or double refunds.
AuthenticationPBKDF2-SHA256 with 350,000 iterations, 15-minute access tokens, rotating refresh tokens with replay detection, HTTP-only Secure SameSite=Strict refresh cookies, role-based access control and account lockout after repeated failed sign-ins.
TransportAll traffic is served over HTTPS/TLS.
AuditabilityEvery administrative action is recorded (who, what changed, before and after, IP address, time) in a queryable audit log.
InfrastructureContainerised services on AWS with managed database, cache and storage, health checks and backups.
Access controlLeast-privilege database roles; platform administration is separated from tenant access.

02Reporting a vulnerability

If you believe you have found a security vulnerability in StoreFlux, please tell us privately so we can fix it before it can be misused. Email admin.storeflux@gmail.com with the subject “Security report”. Please include:

  • a description of the issue and its potential impact;
  • the affected URL, endpoint or component;
  • clear steps to reproduce, with proof-of-concept code or requests if possible;
  • your contact details and how you would like to be credited, if at all.

Our machine-readable contact details are published at /.well-known/security.txt.

03What to expect from us

  • We acknowledge reports within 3 business days.
  • We investigate, keep you updated and aim to resolve confirmed issues promptly, with priority given to severity.
  • We will let you know when the issue is fixed and, with your permission, credit you for the finding.

04Safe harbor

We will not pursue or support legal action against researchers who act in good faith and follow these guidelines. Please:

  • test only against your own stores, or against the public demo store and demo data, never against other customers’ stores;
  • do not access, modify, exfiltrate or retain data that is not yours; if you encounter personal data, stop and report it;
  • do not run denial-of-service, spam, social-engineering or physical attacks;
  • give us a reasonable time to fix the issue before disclosing it publicly.

05Out of scope

  • Findings from automated scanners without a demonstrated impact.
  • Missing security headers or cookie flags without a practical exploit.
  • Rate-limiting or brute-force reports on endpoints that are already limited.
  • Vulnerabilities in third-party services (report these to the vendor), and social engineering of staff or customers.

06Incident response

If we confirm a security incident that affects customer data, we will notify affected merchants without undue delay and in line with our Data Processing Addendum (within 72 hours of becoming aware for personal-data breaches), with the information needed to assess the impact.

Other policies

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Data Processing (DPA)
StoreFlux

The complete headless commerce backend. Build it yourself or let us build it for you.

All systems operational

Product

  • Features
  • API Playground
  • Security
  • Pricing
  • Documentation

Resources

  • Admin panel demo
  • Storefront demo
  • API reference
  • FAQ
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Data Processing (DPA)
  • Security & Disclosure

© 2026 StoreFlux. All rights reserved.

· Built on .NET 10, React 19, and PostgreSQL.

StoreFlux