Security Overview
Sellmaxing is built around practical ecommerce automation security: protected accounts, scoped provider credentials, owner approvals, and clear vulnerability reporting.
Last updated: June 4, 2026
Security posture
Sellmaxing protects customer data with encrypted transport, managed Cloudflare infrastructure, scoped deployment secrets, role-aware workspace access, provider security controls, and operational logging.
Sellmaxing does not currently claim SOC 2, ISO 27001, PCI DSS, or HIPAA compliance unless a signed agreement says otherwise.
Authentication and account protection
Email and password authentication is handled through the app authentication layer. Passwords are not stored in plain text. Customers are responsible for strong passwords and mailbox security.
If you suspect account compromise, contact support@sellmaxing.com and include the account email, workspace name, approximate time, and suspicious activity.
Integration credentials
Store, ad, AI, creative, and fulfillment credentials should be scoped to the minimum permissions needed. Production secrets should be stored in Cloudflare secrets or encrypted integration storage, never committed to source control.
Disconnect unused providers and rotate tokens after team changes, provider warnings, suspected compromise, or accidental exposure.
AI and agent data
Agent workflows may process product candidates, supplier metadata, prompts, generated copy, ad constraints, performance metrics, and order context through connected providers.
Avoid entering regulated data, customer secrets, private credentials, or payment card information into prompts, product notes, or provider credentials unless a workflow explicitly supports that data class.
Operational safeguards
- Use spend caps and owner approvals before scaling campaigns.
- Review generated product claims and creative before publishing.
- Monitor ad account warnings, supplier availability, refund requests, and failed fulfillment jobs.
- Keep production secrets out of Git and rotate exposed credentials immediately.
Responsible disclosure
Report suspected vulnerabilities to support@sellmaxing.com. Do not access, modify, delete, or exfiltrate customer data. Do not run denial-of-service testing, social engineering, spam, or destructive testing.
Include reproduction steps, affected URLs, impact, browser or tooling details, and whether any data was accessed.