Liora is a young company. We won't claim certifications we don't have. Here's exactly what protects your data today, and what we're building toward next.
What's true today
🔐
Credentials encrypted at rest
Every third-party API key and access token (WhatsApp, Shopify, Razorpay, Shiprocket) is encrypted before it’s stored — never saved as plain text.
✅
Every webhook is signature-verified
Shopify, Razorpay, and Meta webhooks are cryptographically verified before we act on them — a request can’t impersonate your store or your payment provider.
🏢
Your data is isolated by business
Every query is scoped to your account. One business’s customer data is structurally never visible to another’s.
🔑
Token-based authentication
Access is verified with signed tokens, not shared secrets passed around in plain headers.
What we're building next
Role-based permissions enforced on every team action, not just defined
A platform-wide audit log covering every automated and admin action
Formal penetration testing once we have the scale to justify it