Security
Updated : 24/09/2026
Encrypted secrets and tokens
Your store's access tokens and the keys of your connected services (Google, WooCommerce) are encrypted at rest with AES-256-GCM, under an application key separate from storage. They are never sent to the browser.
Strict account isolation
Every sensitive table is protected by per-user isolation rules (Row Level Security). A merchant only reaches their own store's data, and every server route re-checks that ownership.
Passwordless sign-in
You sign in with a one-time link sent by e-mail, or with Google. There is no password to steal; sessions are opaque and stored hashed. Staff additionally use two-step verification (6-digit codes).
Hosted in the European Union
The application, the database and e-mails are hosted in France. Some third-party services (card payments, Google sign-in if you choose it, AI engines depending on configuration) may operate outside the EU; they are listed in the privacy policy.
Secure payments
Card payments are operated by a PCI-DSS level 1 certified provider. Storapulse never stores card numbers.
Nothing is published without you
No change is published to your store without your click, nothing is deleted there, and a backup is taken before any replacement. Three support categories are never automatic: refunds, damaged products, cancellations.
Audit log
Sensitive actions (admin switches, publications, credits) are recorded in a timestamped audit log.
Report a vulnerability
Think you found a security issue? Write to support@storapulse.com: we answer quickly and fix with priority.