Security at Sellly
Updated: 28 September 2026
How we protect stores and their customers
- Each business is kept apart. Every record carries its business, every query is limited to it, and automated tests try to cross between businesses on every admin page.
- Logins. Passwords are stored as scrypt hashes and checked against common passwords. Two-step login with an authenticator app is available to everyone and required for Sellly administrators. Changing where money goes, the team or the WhatsApp number, or exporting data, asks for the password again, and owners are emailed.
- Secrets. WhatsApp access tokens and app secrets are encrypted with AES-256-GCM. Session, reset and invitation links are stored only as hashes.
- Our own access. Sellly staff open a store only with a recorded reason, for at most an hour, read-only unless the owner allows changes, and the owners are emailed each time.
- Pages customers see load nothing from other websites and set no cookies.
- Backups of the database and every file are encrypted with a key the server doesn't hold, stored with a different provider, and deleted after 35 days.
- Monitoring. Administrators are alerted to sensitive administrator actions, waves of wrong passwords, bursts of data exports and failed backups.
More detail: Annex 2 of the Data Processing Addendum.
Reporting a vulnerability
If you think you've found a security problem in Sellly, please tell us at [email protected]. Include what you found, how to reproduce it, and what an attacker could do with it.
- We acknowledge reports within 3 working days and keep you updated until it's fixed.
- We aim to fix critical issues within 72 hours, high ones within 7 days, and others within 30 to 90 days.
- We credit you, if you'd like, once it's fixed.
Please: test only against your own account and store; don't access, change or delete other people's data (stop and tell us if you reach any); don't degrade the service (no load or denial-of-service testing); don't use social engineering or physical attacks; and give us 90 days to fix before telling others.
If you follow these rules in good faith, we won't pursue legal action against you for your research, and we'll say so if anyone asks.
Out of scope: reports from automated scanners without a demonstrated impact, missing best-practice headers without an exploit, rate limits on non-sensitive pages, and issues in Meta's, Razorpay's or other providers' own services (report those to them).
Our machine-readable contact is at /.well-known/security.txt.