Security at Kaniva
Your data security is our top priority. We've built Kaniva with enterprise-grade security from the ground up.
Payment Security
We never store your credit card information
How We Handle Payments
- Card data never touches our servers. All payment information goes directly to Stripe or PayPal through their secure, PCI-compliant systems.
- Tokenized transactions. We only store secure tokens that reference your payment method, never actual card numbers.
- CVV/CVC never stored. Security codes are used once for verification and immediately discarded.
- PCI DSS Level 1 partners. Stripe and PayPal maintain the highest level of payment security certification.
Your Store's Data in Its Own Database
One database per store, one Kaniva login per person
Unlike platforms that mix all merchant data together, Kaniva gives each store its own database. The one shared piece is the account itself: a person has a single Kaniva login and can use it at more than one store. Here is what lives where:
Store Data, Separate
Your products, orders, carts, customer profiles, notes and CRM records live in your store's own database, apart from every other store.
Logins, Central
Sign-in details (name, email, password) and which stores a person belongs to live in one central accounts database, so a customer or staff member signs in once. It holds no store data.
Breach Containment
If one store's database were ever compromised, the other stores' data is unaffected.
Easy Data Portability
Your data can be exported without affecting any other merchants.
Performance Isolation
High-traffic stores don't slow down other merchants on the platform.
Encryption Everywhere
Your data is encrypted in transit and at rest
All data transmitted between your browser and our servers is encrypted using 256-bit SSL encryption - the same standard used by banks.
Passwords are hashed using bcrypt with unique salts. Even we cannot see your password - ever.
Digital product files and uploads are stored securely with access controls preventing unauthorized downloads.
Infrastructure Security
Cloudflare in front, hardened servers behind
kaniva.io is served through Cloudflare's proxy, and stores on their own domain are moved behind the same proxy as part of their domain setup. Traffic reaches Cloudflare first, which absorbs denial-of-service floods and filters malicious requests before anything touches our servers, whose addresses stay hidden behind it. Product images and other static files are cached on Cloudflare's global network, so they load from a location near your customer. Behind Cloudflare, Kaniva runs on dedicated hardware, not shared hosting, in a top-tier US data center with redundant power and network and round-the-clock staff.
- DDoS Protection (Cloudflare)
- Web Application Firewall (Cloudflare WAF)
- Automated Backups
- 24/7 Server Monitoring
- Regular Security Updates
- Intrusion Detection
Application Security
Built with security best practices
CSRF Protection
All forms are protected against cross-site request forgery attacks.
SQL Injection Prevention
Parameterized queries prevent malicious database attacks.
XSS Protection
Output encoding prevents cross-site scripting vulnerabilities.
Rate Limiting
API and form submissions are rate-limited to prevent abuse.
Your Role in Security
Security is a shared responsibility. Here's how you can help keep your store secure:
-
1.
Use a strong, unique password
Don't reuse passwords from other sites. Use a password manager if possible.
-
2.
Keep your login credentials private
Never share your password or login as someone else.
-
3.
Log out on shared devices
Always log out when using public or shared computers.
-
4.
Review staff access regularly
Remove access for staff who no longer need it.
Found a Security Issue?
We take security seriously. If you discover a vulnerability, please report it responsibly.
Report Security Issue