Security
How we run and protect a store
What we operate on your behalf, stated as controls rather than adjectives — including what we are not.
Controls
- Isolation
- Every store runs on its own database, its own storage prefix and its own domain. A store is reached at the merchant's own hostname, never at a shared address with an account identifier in the URL.
- Encryption
- HTTPS on every store and every bound domain, issued and renewed for you. Backups and file storage are encrypted at rest.
- Backups
- Automatic daily backups, kept 7 to 90 days depending on your plan, and restorable by you from the control panel. Point-in-time recovery covers a rolling window of about a week.
- Patching
- Security patches and Magento version upgrades are applied by our team, on a schedule we agree with you.
- Extensions
- Extension packages uploaded to a store are scanned before they are built, and a package that ships admin code stays pending until an owner promotes it.
- Infrastructure
- Stoily runs on AWS in us-east-1. You do not operate a server, and there is no server for you to log into.
What we are not
Stoily is not SOC 2 or ISO 27001 certified. We run on AWS, which holds both, and that is Amazon's attestation rather than ours. We would rather write that sentence than let a data center's certificate read as our own.
We publish no availability percentage, and our terms carry no service credits. A number nothing measures and nothing owes is worth less than the architecture behind it, so the architecture is what this page describes.
If you need a security review for procurement, write to us and a person who works on the platform will answer.