Back to Home

    Trust Center

    Last updated: August 1, 2026

    01About This Page

    This page is maintained by Astrixy LLC to answer common security and privacy questions about the Astrixy platform. It describes controls that are enabled today. It is not a certification, an audit report, or independent verification. Where we have not yet completed an independent assessment, we say so plainly on the Security Roadmap.

    02Shared Responsibility

    Security on a commerce platform is a three-way split, and being clear about the boundaries matters more than a long list of features.

    • Astrixy is responsible for the platform: infrastructure, tenant isolation, encryption, authentication mechanisms, audit logging, and secure delivery of the software.
    • You, the merchant, are responsible for your account hygiene — enabling two-factor authentication, managing staff permissions, safeguarding the API keys you connect, configuring retention and consent for your jurisdiction, and the accuracy and legality of what you publish and sell.
    • Your providers are responsible for their own systems. Your payment gateway, courier, and ad platforms operate under your agreements with them; we transmit data to those endpoints on your instruction. They are listed on the Subprocessors page where we engage them ourselves.

    03Access & Authentication

    • Passkeys (WebAuthn) with biometric sign-in, plus TOTP two-factor authentication
    • Role-based access control with least-privilege service roles
    • Session inactivity timeout and per-device session revocation
    • Second factor required for administrative accounts

    04Platform & Hosting

    • Managed Postgres with encryption at rest and point-in-time recovery
    • TLS 1.2+ everywhere with HSTS enforced on all public hostnames
    • Edge CDN with DDoS mitigation and a web application firewall
    • Encrypted backups with documented restore procedures

    05Tenant Isolation

    • Row-level security enforced by the database engine on every tenant-scoped table
    • Public views mask personal data and merchant-confidential fields such as supplier cost and margin
    • Server-side entitlement checks on privileged operations
    • Order totals and prices recomputed server-side from authoritative records

    06Data Collection & Use

    • Data collected is limited to what the Service requires, as described in the Privacy Policy
    • Personal data is not used to train AI models, ours or a vendor's
    • IP addresses are anonymised in analytics; email and tokens are redacted from analytics URLs
    • Consent-gated analytics and advertising tags via an enterprise consent management platform

    07Monitoring & Response

    • Immutable audit logging of privileged operations, retained 12 months
    • Grouped, source-mapped error monitoring with real-time alerting
    • Structured alerting on authentication, payment, and fulfilment failures
    • Automated dependency and secret scanning with a deploy gate on critical findings

    08Payments

    Astrixy does not store raw card numbers. Card data is entered directly into the payment provider's PCI-compliant fields; we retain only a provider reference, the last four digits, and the card brand for display. Subscription billing for Astrixy itself runs through our merchant of record. Buyer payments on merchant storefronts are processed by the merchant's own gateway, and Astrixy does not hold those funds.

    09Retention, Deletion & Privacy Requests

    Live tenant data is deleted within 30 days of account termination, with export available throughout that window. Encrypted backups age out on a 35-day rolling cycle. Financial records required for tax and anti-fraud purposes are kept for the statutory period in a restricted archive. Individual data subject requests — access, correction, deletion, portability, objection — are handled within 30 days; see the GDPR page and the Privacy Policy.

    10Compliance Posture

    We operate under the GDPR as a processor for merchant data and as a controller for our own account data, with Standard Contractual Clauses covering transfers out of the EEA. Our Data Processing Agreement is available without signature. We are not currently SOC 2 or ISO 27001 certified and make no such claim; our intended path to independent assessment is published on the Security Roadmap.

    11Reporting & Contact

    Security vulnerabilities: security@astrixy.app — see Responsible Disclosure for scope and safe harbour.
    Data protection: dpo@astrixy.app
    Abuse and content: abuse@astrixy.app
    Vendor assessments and questionnaires: security@astrixy.app

    Further reading: Security FAQ, Subprocessors, Service Level Agreement, Legal Center.