Security
Security at StoreFleet
This page lists the controls that exist in the StoreFleet platform today and what each one does. It makes no certification claims.
Two-factor sign-in
An admin can switch on two-factor sign-in for the whole workspace. From then on, every member who has not set it up is asked to at their next sign-in, with an authenticator app and one-time recovery codes.
- One workspace-wide setting, not a choice each person makes
- Turning the setting on or off is written to the audit log
Roles and access
Every member is an admin, a manager or staff. Admins invite, edit and remove members and read the audit log. Admins and managers can approve changes. Staff can be limited to the screens and the shops you choose.
- Admins and managers see every screen; staff see only the screens granted to them
- A staff member with no shop assigned can see every shop, so assign at least one
Audit log
Sign-ins and failed sign-ins, password changes, invitations, role, screen and shop changes and other sensitive actions are recorded, newest first. Only admins can read the log.
Approval before changes reach live shops
Each kind of change to a live shop has a level: automatic, approval required, or owner only. A pending change shows a before-and-after and how many objects it touches, and it is flagged when it cannot be undone. Nothing changes until someone approves.
- Refunds, cancellations, captures and deletes are always owner-only, and the level cannot be relaxed
- Inventory levels, product SEO and discounts need approval by default; low-risk changes such as product tags apply automatically by default
- Levels can be set for each shop in Approval Settings
Alerts without buyer contact data
Alerts sent to Discord and Telegram carry a fixed set of fields: order number, total, currency, shop name, status, tracking number, carrier and a reason. A buyer’s name, email and address are not among them, and any field outside that list is rejected.
Shopper tracking links
A tracking link shows the order number, the shop, the status, each package with its carrier scans and the items in the order. It never shows the buyer’s email, an address or an amount.
- A wrong, expired or revoked link gets the same message, so a failed link does not reveal whether it ever existed
- Lookups are rate limited, and the page is not cached and is kept out of search engines
Report a problem
If you have found a security problem, write to [email protected]. The same contact is published in our security.txt.