Security at AgenticEcom

Security at AgenticEcom

How we secure our products, our infrastructure, and your data.

Module audits — EQP, public

Every AgenticEcom module is audited under Adobe's Extension Quality Programme (EQP) before release. The full audit report is linked from each module's product page. Items: code quality, security checks, compatibility, performance, documentation. Current status: 40+ modules PASS.

Astro Frontend security audit

The AgenticEcom Astro Frontend carries a separately-commissioned security audit. The full report is available on request. Headline: 1 critical (now fixed), 5 high (fixed), 9 medium (fixed/scheduled), 8 low (scheduled), 24 positive findings. We don't hide findings; we publish them and the fixes.

Code-level practices

  • Constant-time crypto for all secret comparisons (token verification, HMAC validation, etc.).
  • HMAC-signed sessions for the Astro admin shell.
  • Strict Content Security Policy (CSP) on the Astro storefront.
  • Rate-limited login on both Magento admin and Astro admin.
  • CMS HTML sanitisation in three places (input on save, render on output, second sanitisation on cross-domain reflection).
  • No secrets in source control — environment variables only, with a check in CI.

Infrastructure

  • UK-based VPS providers for DFY-hosted stores (managed by us).
  • Daily off-site encrypted backups; tested restore quarterly.
  • TLS 1.2+ enforced; HSTS with 1-year max-age; cert auto-renewed.
  • WAF (web-application firewall) in front of every DFY-hosted Magento.
  • Operating-system and Magento patches applied within 14 days of upstream release for non-critical, 48 hours for critical.

Reporting a vulnerability

If you've found a security issue in any AgenticEcom product or in agenticecom.net, please email support@agenticecom.net with subject "SECURITY". We follow coordinated disclosure: we acknowledge within 1 business day, fix critical issues within 14 days, and publicly credit you (with your permission) when the fix ships.

We don't currently run a paid bug-bounty program; we send hand-written thanks and visible credit. Plans for a bounty in 2027 as we scale.

Compliance posture

  • GDPR-ready (UK and EU). Full DPA on request.
  • PCI-DSS: we don't store card data; payment processors handle it under their own PCI compliance.
  • SOC 2 / ISO 27001: not yet certified; on the roadmap for 2027.
  • HMRC-aligned retention for UK sales records.

Contact

Security: support@agenticecom.net