A small brand cannot employ a security team — so its platform has to be one. This post lays out, concretely, what CommerceOS does to protect your store and your customers, and the short list of what still belongs to you.
Every store isolated at the database
CommerceOS is multi-tenant: many stores, one platform. The most important promise in that sentence is isolation, and ours is enforced at the database layer with row-level security — the database itself refuses to return one store's rows to another store's queries. It is not a convention our code follows; it is a wall our code cannot climb. Your catalog, customers and orders are yours alone.
Sign-in that survives a stolen password
Passwords leak — reused ones especially. CommerceOS staff sign-in supports two-factor authentication with authenticator apps (the six-digit-code kind, no SMS dependency) plus recovery codes for the day your phone drowns. Turning it on takes two minutes in settings and is the single best thing you can do for your store's security today.
Card numbers we never see
Checkout card fields are hosted by your payment provider — the secure inputs belong to Razorpay or Stripe, not to CommerceOS. Card numbers never touch our servers, which keeps your store in the strictest, simplest category of card-security compliance without paperwork on your side. UPI flows likewise run through your gateway's own checkout.
An audit trail for every admin action
When something looks odd — a price changed, a discount appeared — the question is always who did that, and when. Every admin action on CommerceOS is audit-logged. With staff accounts, that record is the difference between a mystery and a two-minute answer.
Boring, invisible, constant
The unglamorous layer: encrypted connections everywhere, managed infrastructure that is patched without your involvement, backups you never have to schedule, and the same build pipeline that enforces our speed budget refusing changes that fail security review. You see none of it, which is the point.
What still belongs to you
Honesty requires the short list of things no platform can do for you:
- Use a long, unique password for your store — a password manager makes this free.
- Turn on 2FA and store the recovery codes somewhere that is not your phone.
- Give staff their own accounts instead of sharing yours — the audit log only helps if names mean something.
- Be suspicious of urgent messages asking you to "verify" your login. We will never ask for your password or codes.
Do those four, and the rest — isolation, hosted payments, audit trails, patched servers — is already running, quietly, on every store. Including the one you could open today for ₹0.