Security

Security controls designed into the product and delivery process.

Logivio uses company-scoped data access, regression coverage, secure configuration checks and explicit billing safeguards. This page describes current principles without claiming certifications that have not been obtained.

Ask a security question
Tenant boundaries. Operational records are scoped to the owning company.
Authentication controls. Protected workflows require authenticated access.
Regression coverage. Security-sensitive behaviour is protected by automated tests.
Secret management. Production credentials are supplied through environment configuration rather than committed to source.
Billing safeguards. Stripe webhooks are verified, idempotent and cannot grant access from browser redirects.
Operational health. Deployment checks, readiness endpoints and billing health monitoring surface important failures.
Information security programme

Published controls for how Logivio protects operational data.

Security-affecting changes are reviewed through pull requests, must pass automated CI, and are deployed from traceable commits. Controls are reviewed when the architecture, subprocessors, connected marketplaces or personal-data handling changes.

Access control

Least privilege and tenant ownership.

Customer data is scoped to the owning company. Marketplace credentials, OAuth state and operational sync controls are restricted to authorised privileged paths. Production secrets stay in managed environment configuration rather than source control.

Data classification

Public, Internal, Confidential and Restricted.

Customer account, order, inventory, buyer and business data is treated as Confidential. Passwords, database credentials, API secrets and marketplace tokens are Restricted. Sensitive traffic uses HTTPS/TLS and production data and backups use managed encryption at rest.

Vulnerability management

Release gates fail closed.

Production releases include Django deployment checks, Logivio security audits, dependency vulnerability checks and secret-pattern checks. Security fixes are applied through reviewed, CI-validated commits.

Incident response

Contain, preserve evidence, rotate and recover.

Suspected compromise triggers traffic restriction where necessary, preservation of operational evidence, credential rotation, recovery from a known-good release and verified backups, followed by tenant and billing checks before normal operation resumes.

Data protection

Access follows company ownership.

Application queries and workflows are designed around tenant scope. Tests cover cross-company access risks in important operational areas.

View privacy policy
Responsible disclosure

Report security concerns directly.

Do not include sensitive customer data in an initial report. Provide the affected page, observed behaviour and steps required to reproduce the issue.

Report a security issue

Need security or privacy information?

Use the contact form for product-security, privacy or due-diligence questions.

Contact Logivio