TRUST CENTRE

Security at ShopCiravo

Practical safeguards designed for the customer, sales, invoice, and inventory information your business relies on.

Last updated: August 13, 2026

Tenant separation

ShopCiravo is designed as a multi-tenant service. Business records are associated with a specific workspace, and application controls are used to keep one customer's data separate from another customer's data.

Access controls

Authentication, session controls, and workspace membership are used to limit access to authorized users. The private owner console is separated from customer workspaces and records administrative licensing actions in an audit trail.

Data protection

Data is transmitted over encrypted HTTPS connections. Cloud data and uploaded business assets are stored using managed infrastructure designed for availability and controlled access.

Operational safeguards

We follow practices intended to reduce risk, including least-privilege access, secret management, change review, dependency maintenance, logging, and recoverable deployment versions.

Customer responsibilities

Security is shared. Customers should use secure account access, remove former employees promptly, keep devices and browsers updated, review unusual activity, and avoid placing highly sensitive information in free-form fields when it is not needed.

Reporting a vulnerability

Please report a suspected vulnerability privately to hello@shopciravo.com. Include the affected page or feature, steps to reproduce, and potential impact. Do not access customer data, disrupt the service, or publicly disclose an unresolved issue.