Security approach
Adherely uses layered administrative, technical, and operational safeguards appropriate to the service. No online system can promise absolute security, so safeguards are reviewed as the product, risks, and providers change.
Current safeguards
- Managed merchant authentication and protected dashboard routes.
- Shop-scoped authorization checks for merchant data and actions.
- Encrypted store credentials and server-only secret handling.
- Signed webhook verification, bounded request bodies, idempotency, and replay controls for commerce and messaging events.
- Restricted database access, row-level security, data minimization, and defined retention windows for short-lived operational records.
- Provider review, recovery procedures, operational monitoring, and documented escalation for suspected incidents.
Incident response
When Adherely receives a credible security or privacy report, it records and triages the issue, limits access to incident information, preserves relevant evidence, contains the risk, removes the cause, validates recovery, and documents follow-up work. Severity is based on exploitability, data sensitivity, affected people and merchants, service impact, and whether misuse is ongoing.
Adherely will notify affected merchants, individuals, providers, or authorities when required by applicable law or contract. Processor commitments for merchant customer data are described in the Data Processing Addendum.
Report a vulnerability
Email support@adherely.co with the subject “Security report.” Describe the affected URL or component, the observed behavior, safe reproduction steps, and a way to contact you. For a suspected privacy incident, email privacy@adherely.co. Do not include passwords, authentication tokens, full payment credentials, unnecessary personal data, or another person's private hub link.
Responsible testing
Act in good faith, use only accounts and data you control, minimize access, stop if you encounter another person's data, and do not disrupt availability, send unsolicited messages, use social engineering, or destroy or alter data. Give Adherely reasonable time to investigate before public disclosure. This page does not create a bug-bounty payment promise or authorize conduct prohibited by law.
Privacy and service providers
Read the Privacy Policy for retention and verified deletion requests, and the Subprocessors page for the providers used to operate Adherely.