Last updated 23 July 2026

Product security, made practical.

Emberex applies data minimisation, access control, encryption, environment separation, audit logging, retention and incident-response controls to reduce unauthorised access, disclosure, alteration and loss.

Data loss prevention

  • Collect only the customer fields required for an enabled review flow.
  • Pseudonymise verified-customer and administrator identifiers.
  • Use HTTPS, provider-managed encrypted storage, private database networking and encrypted backups.
  • Keep development, beta and production databases, buckets, credentials and services separate.
  • Redact token, secret, authorisation, cookie, password and email fields from application logs.
  • Record access to review-management routes and expire those records after 365 days.
  • Delete temporary verification context and honour Shopify customer and shop redaction webhooks.

Incident response

Emberex triages reports, contains affected credentials and services, preserves privacy-safe evidence, identifies affected shops and data, restores from verified infrastructure and backups, and notifies affected merchants and authorities where legally required. Corrective actions are tracked through completion and followed by a post-incident review.

Report a concern

Use the security contact form and include the affected page or component, observed behaviour, reproduction steps and potential impact. Do not include passwords, access tokens, private keys, payment information, live customer review data or unnecessary personal information.

Safe research

Do not disrupt service, access another person's account or data, use social engineering, send automated high-volume traffic, or retain information beyond what is needed to describe the issue. This page does not authorise testing of Etsy, Shopify, Railway, Resend or another third-party service.