Skip to content
Security

How we run and protect a store

What we operate on your behalf, stated as controls rather than adjectives — including what we are not.

Controls

Isolation
Every store runs on its own database, its own storage prefix and its own domain. A store is reached at the merchant's own hostname, never at a shared address with an account identifier in the URL.
Encryption
HTTPS on every store and every bound domain, issued and renewed for you. Backups and file storage are encrypted at rest.
Backups
Automatic daily backups, kept 7 to 90 days depending on your plan, and restorable by you from the control panel. Point-in-time recovery covers a rolling window of about a week.
Patching
Security patches and Magento version upgrades are applied by our team, on a schedule we agree with you.
Extensions
Extension packages uploaded to a store are scanned before they are built, and a package that ships admin code stays pending until an owner promotes it.
Infrastructure
Stoily runs on AWS in us-east-1. You do not operate a server, and there is no server for you to log into.

What we are not

Stoily is not SOC 2 or ISO 27001 certified. We run on AWS, which holds both, and that is Amazon's attestation rather than ours. We would rather write that sentence than let a data center's certificate read as our own.

We publish no availability percentage, and our terms carry no service credits. A number nothing measures and nothing owes is worth less than the architecture behind it, so the architecture is what this page describes.

If you need a security review for procurement, write to us and a person who works on the platform will answer.

Ask a security question