Protected credentials
The shared Daraz App Secret and seller tokens are encrypted before database storage. The server encryption key is kept outside the database and must be backed up privately.
sellerby applies account, store and database boundaries throughout authorization and record access.
The shared Daraz App Secret and seller tokens are encrypted before database storage. The server encryption key is kept outside the database and must be backed up privately.
Orders, products, costs, expenses, invoices and finance reads include the active store identity associated with the signed-in member.
The platform administrator manages shared integration settings and account status. Members cannot access administrator pages.
Changing a password or suspending an account increments its session version so older sessions stop working.
Web-server rules block direct access to configuration, database scripts, internal includes, tests and storage paths.
User-facing errors avoid exposing secrets or raw provider responses. Server logs use short references for investigation.
The site owner must protect hosting access, database credentials and the original config/encryption.local.php file. HTTPS, PHP OpenSSL, PHP cURL and PDO MySQL must stay enabled. Backups should include both the database and encryption key.
No web application can promise absolute security. sellerby reduces common exposure paths and preserves clear recovery boundaries when configuration needs attention.