Security
Last updated 10 October 2026
How this store protects your money, your account and your data. The numbers on this page come from the store's live settings, so they always match what the server enforces.
Your balance
- Every change to a balance is one entry in an append-only ledger. Entries are never edited or deleted: a correction is a new entry, and the database itself refuses to change one.
- A balance can never go below zero, and an order is charged once and refunded at most once.
- An order a supplier rejects or can't deliver is refunded to your balance automatically.
Your account
- Passwords are stored only as salted Argon2 hashes.
- After
5 failed sign-insan account is locked for15 minutes. - Email codes expire after
10 minutes. After10 wrong codesfrom one network, codes are refused for15 minutes. - Two-factor authentication is available to everyone and required for staff.
- A sign-in lasts at most
12 hours.
Reseller API keys
- A key works only from the IP address it is bound to.
- After
10 failed key checksfrom one address, it is refused for15 minutes. - Keys are stored hashed: once created, a key can't be shown again, only replaced.
Data we encrypt
- Delivered codes (unlock codes and check results), supplier credentials and two-factor secrets are encrypted at rest.
- Card payments go through Stripe's own checkout page: card numbers never reach this store.
Staff access
- Every change staff make in the admin panel is written to an audit log.
- Each staff member sees only the parts of the panel their role allows.
Found a problem?
Tell us through the contact page. Please don't test against other customers' accounts or orders.