256-bit
SSL Encryption
1 per store
Store Databases
PCI
Compliant Payments
24/7
Monitoring

Payment Security

We never store your credit card information

How We Handle Payments

  • Card data never touches our servers. All payment information goes directly to Stripe or PayPal through their secure, PCI-compliant systems.
  • Tokenized transactions. We only store secure tokens that reference your payment method, never actual card numbers.
  • CVV/CVC never stored. Security codes are used once for verification and immediately discarded.
  • PCI DSS Level 1 partners. Stripe and PayPal maintain the highest level of payment security certification.
Stripe PayPal

Your Store's Data in Its Own Database

One database per store, one Kaniva login per person

Unlike platforms that mix all merchant data together, Kaniva gives each store its own database. The one shared piece is the account itself: a person has a single Kaniva login and can use it at more than one store. Here is what lives where:

Store Data, Separate

Your products, orders, carts, customer profiles, notes and CRM records live in your store's own database, apart from every other store.

Logins, Central

Sign-in details (name, email, password) and which stores a person belongs to live in one central accounts database, so a customer or staff member signs in once. It holds no store data.

Breach Containment

If one store's database were ever compromised, the other stores' data is unaffected.

Easy Data Portability

Your data can be exported without affecting any other merchants.

Performance Isolation

High-traffic stores don't slow down other merchants on the platform.

Encryption Everywhere

Your data is encrypted in transit and at rest

TLS 1.3 / SSL Encryption

All data transmitted between your browser and our servers is encrypted using 256-bit SSL encryption - the same standard used by banks.

Encrypted Passwords

Passwords are hashed using bcrypt with unique salts. Even we cannot see your password - ever.

Secure File Storage

Digital product files and uploads are stored securely with access controls preventing unauthorized downloads.

Infrastructure Security

Cloudflare in front, hardened servers behind

kaniva.io is served through Cloudflare's proxy, and stores on their own domain are moved behind the same proxy as part of their domain setup. Traffic reaches Cloudflare first, which absorbs denial-of-service floods and filters malicious requests before anything touches our servers, whose addresses stay hidden behind it. Product images and other static files are cached on Cloudflare's global network, so they load from a location near your customer. Behind Cloudflare, Kaniva runs on dedicated hardware, not shared hosting, in a top-tier US data center with redundant power and network and round-the-clock staff.

  • DDoS Protection (Cloudflare)
  • Web Application Firewall (Cloudflare WAF)
  • Automated Backups
  • 24/7 Server Monitoring
  • Regular Security Updates
  • Intrusion Detection

Application Security

Built with security best practices

CSRF Protection

All forms are protected against cross-site request forgery attacks.

SQL Injection Prevention

Parameterized queries prevent malicious database attacks.

XSS Protection

Output encoding prevents cross-site scripting vulnerabilities.

Rate Limiting

API and form submissions are rate-limited to prevent abuse.

Your Role in Security

Security is a shared responsibility. Here's how you can help keep your store secure:

  • 1.
    Use a strong, unique password

    Don't reuse passwords from other sites. Use a password manager if possible.

  • 2.
    Keep your login credentials private

    Never share your password or login as someone else.

  • 3.
    Log out on shared devices

    Always log out when using public or shared computers.

  • 4.
    Review staff access regularly

    Remove access for staff who no longer need it.