Security at AgenticEcom
Security at AgenticEcom
How we secure our products, our infrastructure, and your data.
Module audits — EQP, public
Every AgenticEcom module is audited under Adobe's Extension Quality Programme (EQP) before release. The full audit report is linked from each module's product page. Items: code quality, security checks, compatibility, performance, documentation. Current status: 40+ modules PASS.
Astro Frontend security audit
The AgenticEcom Astro Frontend carries a separately-commissioned security audit. The full report is available on request. Headline: 1 critical (now fixed), 5 high (fixed), 9 medium (fixed/scheduled), 8 low (scheduled), 24 positive findings. We don't hide findings; we publish them and the fixes.
Code-level practices
- Constant-time crypto for all secret comparisons (token verification, HMAC validation, etc.).
- HMAC-signed sessions for the Astro admin shell.
- Strict Content Security Policy (CSP) on the Astro storefront.
- Rate-limited login on both Magento admin and Astro admin.
- CMS HTML sanitisation in three places (input on save, render on output, second sanitisation on cross-domain reflection).
- No secrets in source control — environment variables only, with a check in CI.
Infrastructure
- UK-based VPS providers for DFY-hosted stores (managed by us).
- Daily off-site encrypted backups; tested restore quarterly.
- TLS 1.2+ enforced; HSTS with 1-year max-age; cert auto-renewed.
- WAF (web-application firewall) in front of every DFY-hosted Magento.
- Operating-system and Magento patches applied within 14 days of upstream release for non-critical, 48 hours for critical.
Reporting a vulnerability
If you've found a security issue in any AgenticEcom product or in agenticecom.net, please email support@agenticecom.net with subject "SECURITY". We follow coordinated disclosure: we acknowledge within 1 business day, fix critical issues within 14 days, and publicly credit you (with your permission) when the fix ships.
We don't currently run a paid bug-bounty program; we send hand-written thanks and visible credit. Plans for a bounty in 2027 as we scale.
Compliance posture
- GDPR-ready (UK and EU). Full DPA on request.
- PCI-DSS: we don't store card data; payment processors handle it under their own PCI compliance.
- SOC 2 / ISO 27001: not yet certified; on the roadmap for 2027.
- HMRC-aligned retention for UK sales records.
Contact
Security: support@agenticecom.net
