Security
Your books are our responsibility
sild holds the key to your Merit company. This page says how we look after it and your customers' data, with no small print.
The essentials01 / 03
Four things worth knowing
If you only read one part, read this one.
Your Merit key, locked away
Encrypted, never in WordPress or in logs. Delete it in Merit and access ends that moment.
Data stays in the EU
Servers are in the European Union, and everything is processed under the GDPR.
Read only first
Preview mode writes nothing to Merit. You switch to live yourself.
Only what an invoice needs
Card details, passwords and delivery addresses never reach us.
Technical02 / 03
What is under the hood
Encryption
Merit keys, store secrets and order data are encrypted in the database (AES-256). Connections go over HTTPS only.
Signed requests
Every request between your shop and sild is signed with the shop's own secret, a timestamp and a one-time value, so a recorded request cannot be replayed.
Short retention
Data of a finished order is deleted after 60 days. Logs hold no order contents and no keys.
Hardened servers
Key-only sign-in, a firewall, automatic security updates and request limits.
Encrypted backups
A backup runs every night, encrypted with a key that is not on the server. Restores are tested.
Constant monitoring
The database, queues, backups and disk space are checked every five minutes.
If you leave03 / 03
Leaving is as easy as joining
- 1
Disconnect
When the last shop disconnects, the Merit key is deleted.
- 2
Data deleted
The remaining data is deleted within 30 days, and backups roll over in 14 more.
- 3
Invoices stay yours
Everything sild created is in your Merit and stays there.
Documents
- Data processing agreement: how we process your customers' data for you.
- Subprocessors: who else touches the data.
- Privacy policy: what we collect about you.
Found a vulnerability?
Write to support@sild.cloud. We answer within two business days and take no action against anyone who reports in good faith.