Security

Last updated 20 September 2026

You are handing this service your customers' conversations and the keys to your store. Here is what actually stands behind that. We hold no security certifications, and we are not going to imply otherwise.

Accounts

  • Passwords are hashed with Argon2. We cannot read yours, and a database dump does not contain it.
  • A failed sign in says the same thing whether or not the email exists, so the form cannot be used to find out who has an account.
  • Sign in attempts are rate limited.
  • Session cookies are HTTP-only, so page scripts cannot read them, and carry the Secure flag in production.

Money

  • The agent cannot refund, cancel or reprice anything on its own. Those stop and wait for a person.
  • A refund from merchant mode needs a six digit code sent to your own number, good for five minutes and one use. Three wrong tries locks it for an hour, and the session expires after thirty minutes idle.
  • A refund re-verifies even inside a session that is already elevated, because a price you can see and undo is not a refund that is gone.
  • Card numbers never reach us. SSLCommerz and Stripe take the payment and hand back a result.
  • A payment notification is a claim, not a fact. Nothing is applied until we confirm it with the gateway over a connection we opened, and the amount is checked against our own invoice rather than the one in the message.

Your data

  • Every query is scoped to your shop. One shop cannot read another's conversations, contacts or orders.
  • Attachments live in a private bucket and are served through an endpoint that checks your session first. There are no guessable public URLs.
  • The database key that bypasses those checks is server-side only and is never sent to a browser.
  • The action log is append-only at the database level: what the agent did cannot be quietly edited afterwards, by us or by anyone else.

Channels

  • Inbound webhooks are signature-checked against the app secret before anything is read. An unsigned POST is refused.
  • Each message carries a deduplication key, so a delivery retried by Meta is not answered twice.
  • Per-shop channel tokens are stored per connection, not shared, and disconnecting a channel stops it immediately.

Reporting a problem

Write to security@easyalap.com. Tell us what you found and how to reproduce it. We will confirm within 5 working days, we will not threaten you, and we will credit you if you want to be credited.