🔒 Security

How your data is protected

No certificates to wave around yet — just concrete measures, described honestly enough that you can judge them yourself.

Infrastructure

Encryption

Access control

Application security

Backups and recovery

Incident response

  1. Contain — isolate the affected component, revoke exposed credentials, stop further data flow.
  2. Assess — establish what data was involved and which stores are affected, using server and application logs.
  3. Notify — inform affected merchants without undue delay, and the supervisory authority within 72 hours where a personal data breach has occurred.
  4. Remediate — fix the root cause, deploy, verify.
  5. Review — document what happened and what changed so it cannot repeat.

Reporting a vulnerability

Email app@liutomedia.lt with steps to reproduce. We confirm receipt quickly, keep you informed while we fix it, and are happy to credit you. Please do not test against stores that are not your own, and give us reasonable time before disclosing publicly.

What we do not claim

We have no SOC 2, ISO 27001 or third-party penetration test yet. When that changes, it will be stated here with the date and the auditor — not before. If your organisation requires a formal audit before installing, write to us and we will tell you honestly where we stand.

See also: privacy policy · terms and DPA · GDPR & CCPA