Storapulse

Security

Updated : 24/09/2026

Encrypted secrets and tokens

Your store's access tokens and the keys of your connected services (Google, WooCommerce) are encrypted at rest with AES-256-GCM, under an application key separate from storage. They are never sent to the browser.

Strict account isolation

Every sensitive table is protected by per-user isolation rules (Row Level Security). A merchant only reaches their own store's data, and every server route re-checks that ownership.

Passwordless sign-in

You sign in with a one-time link sent by e-mail, or with Google. There is no password to steal; sessions are opaque and stored hashed. Staff additionally use two-step verification (6-digit codes).

Hosted in the European Union

The application, the database and e-mails are hosted in France. Some third-party services (card payments, Google sign-in if you choose it, AI engines depending on configuration) may operate outside the EU; they are listed in the privacy policy.

Secure payments

Card payments are operated by a PCI-DSS level 1 certified provider. Storapulse never stores card numbers.

Nothing is published without you

No change is published to your store without your click, nothing is deleted there, and a backup is taken before any replacement. Three support categories are never automatic: refunds, damaged products, cancellations.

Audit log

Sensitive actions (admin switches, publications, credits) are recorded in a timestamped audit log.

Report a vulnerability

Think you found a security issue? Write to support@storapulse.com: we answer quickly and fix with priority.

Storapulse — securite