01About This Page
This page is maintained by Astrixy LLC to answer common security and privacy questions about the Astrixy platform. It describes controls that are enabled today. It is not a certification, an audit report, or independent verification. Where we have not yet completed an independent assessment, we say so plainly on the Security Roadmap.
03Access & Authentication
- Passkeys (WebAuthn) with biometric sign-in, plus TOTP two-factor authentication
- Role-based access control with least-privilege service roles
- Session inactivity timeout and per-device session revocation
- Second factor required for administrative accounts
04Platform & Hosting
- Managed Postgres with encryption at rest and point-in-time recovery
- TLS 1.2+ everywhere with HSTS enforced on all public hostnames
- Edge CDN with DDoS mitigation and a web application firewall
- Encrypted backups with documented restore procedures
05Tenant Isolation
- Row-level security enforced by the database engine on every tenant-scoped table
- Public views mask personal data and merchant-confidential fields such as supplier cost and margin
- Server-side entitlement checks on privileged operations
- Order totals and prices recomputed server-side from authoritative records
06Data Collection & Use
- Data collected is limited to what the Service requires, as described in the Privacy Policy
- Personal data is not used to train AI models, ours or a vendor's
- IP addresses are anonymised in analytics; email and tokens are redacted from analytics URLs
- Consent-gated analytics and advertising tags via an enterprise consent management platform
07Monitoring & Response
- Immutable audit logging of privileged operations, retained 12 months
- Grouped, source-mapped error monitoring with real-time alerting
- Structured alerting on authentication, payment, and fulfilment failures
- Automated dependency and secret scanning with a deploy gate on critical findings
08Payments
Astrixy does not store raw card numbers. Card data is entered directly into the payment provider's PCI-compliant fields; we retain only a provider reference, the last four digits, and the card brand for display. Subscription billing for Astrixy itself runs through our merchant of record. Buyer payments on merchant storefronts are processed by the merchant's own gateway, and Astrixy does not hold those funds.
09Retention, Deletion & Privacy Requests
Live tenant data is deleted within 30 days of account termination, with export available throughout that window. Encrypted backups age out on a 35-day rolling cycle. Financial records required for tax and anti-fraud purposes are kept for the statutory period in a restricted archive. Individual data subject requests — access, correction, deletion, portability, objection — are handled within 30 days; see the GDPR page and the Privacy Policy.
10Compliance Posture
We operate under the GDPR as a processor for merchant data and as a controller for our own account data, with Standard Contractual Clauses covering transfers out of the EEA. Our Data Processing Agreement is available without signature. We are not currently SOC 2 or ISO 27001 certified and make no such claim; our intended path to independent assessment is published on the Security Roadmap.
11Reporting & Contact
Security vulnerabilities: security@astrixy.app — see Responsible Disclosure for scope and safe harbour.
Data protection: dpo@astrixy.app
Abuse and content: abuse@astrixy.app
Vendor assessments and questionnaires: security@astrixy.app
Further reading: Security FAQ, Subprocessors, Service Level Agreement, Legal Center.