sellerby.
SECURITY BY DESIGN

Seller access stays separated and controlled.

sellerby applies account, store and database boundaries throughout authorization and record access.

Protected credentials

The shared Daraz App Secret and seller tokens are encrypted before database storage. The server encryption key is kept outside the database and must be backed up privately.

Store-scoped records

Orders, products, costs, expenses, invoices and finance reads include the active store identity associated with the signed-in member.

One administrator

The platform administrator manages shared integration settings and account status. Members cannot access administrator pages.

Session controls

Changing a password or suspending an account increments its session version so older sessions stop working.

Private server files

Web-server rules block direct access to configuration, database scripts, internal includes, tests and storage paths.

Safe error messages

User-facing errors avoid exposing secrets or raw provider responses. Server logs use short references for investigation.

Operational responsibility

The site owner must protect hosting access, database credentials and the original config/encryption.local.php file. HTTPS, PHP OpenSSL, PHP cURL and PDO MySQL must stay enabled. Backups should include both the database and encryption key.

No web application can promise absolute security. sellerby reduces common exposure paths and preserves clear recovery boundaries when configuration needs attention.