MultiVendorOS

Security & Incident Response

Last updated 29 July 2026

This page describes the controls that protect data held by MultiVendorOS, and exactly what happens when something goes wrong. It is written to be checked, not to sound reassuring — every control below is one that can be verified.

1. What we hold

The app holds order data, vendor business records, and an append-only financial ledger. From the customer, it holds only name and shipping address — a vendor cannot post a parcel without them. It does not hold customer email addresses, phone numbers, billing addresses, or payment details, and it never holds card data of any kind.

2. Controls

In transit

At rest

Isolation

Integrity

Backups

Access

3. What happens during an incident

An incident is any event that may have exposed data, altered financial records, or made the service unavailable.

StageTargetWhat happens
Detect Error alerting, failed-login monitoring, and the ledger reconciliation check that runs on every payout.
Contain Within 1 hour of confirming Revoke affected tokens, disable the affected path, or take the service offline. Stopping the bleeding comes before diagnosing it.
Assess Within 24 hours Determine what data was reachable, for how long, and by whom, from audit and access logs.
Notify Within 72 hours Affected merchants are emailed directly with what we know, what we do not yet know, and what they should do. Shopify is notified where their platform or their merchants are affected. We do not wait for a complete picture before telling people.
Remediate Fix the cause, not the symptom. Rotate every credential that was in scope.
Review Within 14 days Written post-incident review: what happened, why it was possible, what changed so it cannot happen the same way again. Shared with affected merchants on request.

We will tell you even when it is embarrassing. If we cause a problem, you hear it from us first, with the facts. A merchant discovering an incident from someone else is a worse outcome than the incident.

4. Reporting a vulnerability

Email security@multivendoros.com with steps to reproduce. We acknowledge within two business days and will keep you updated until it is resolved.

We will not pursue legal action against anyone who reports a vulnerability in good faith, gives us reasonable time to fix it, and does not access, modify or delete other people's data while investigating.

Please do not run automated scanners against production, run denial-of-service tests, or use social engineering against our staff or merchants.

5. What we do not claim

We hold no SOC 2, ISO 27001 or PCI certification, and we do not imply otherwise. We do not process card payments — Shopify handles merchant billing and vendor payouts move through the merchant's own bank or a licensed payment provider.

6. Contact

Security: security@multivendoros.com
Privacy: privacy@multivendoros.com
Support: support@multivendoros.com