Security
Built secure.
Plain words about how we protect your website, your store and your customers. We only list what is actually in place today.
What protects you
Locked connection, everywhere
Every Wannlabs page and app (wannlabs.com, Ember, OpenSign and Prime) only loads over HTTPS, so what you type travels encrypted.
One careful sign-in
One Wannlabs account works across our apps. New accounts confirm their email first, and sign-ups are checked for throwaway emails and too many attempts.
Your data stays yours
In Ember Cloud, each app’s data is locked so every person can only see and change their own rows. The database itself enforces this, not just the app.
Encrypted when stored
Prime messages and files, and data saved in Ember Cloud, are encrypted when stored, with a separate key for each account or project.
Extra encryption in Prime
Prime, our assistant for mortgage brokers, adds its own layer of encryption to messages between your browser and our servers, on top of HTTPS.
Payments by Stripe
You pay on Stripe’s secure checkout page. Your card number goes to Stripe and never touches our servers.
Fair limits, enforced
Plan limits and AI points are checked on our servers, so nobody can get around them from their browser.
Screening for abuse
Ember checks requests, code and published sites for scams, malware and illegal content. Accounts that keep trying get paused for review.
AI asks before risky changes
Before Ember makes a big or risky change (like touching sign-in, payments or your data) it tells you and waits for your OK. Prime waits for your approval before sending anything.
Admin access is logged
Sensitive admin actions, like an admin viewing an account for support, are recorded in an audit log.
Google access, carefully
Connecting your Google account is in early access: we turn it on account by account, and you can disconnect it any time from your dashboard.
Nightly backups
Our account and app databases are backed up every night to a separate disk, so we can recover from mistakes or hardware trouble.
What we don’t claim
We don’t hold security certifications like SOC 2, HIPAA or PCI today, and we won’t say we do. Card payments are handled by Stripe. No system is perfect, so we keep improving and we want to hear about problems.
Report a security issue
Found something that looks wrong? Email us and we’ll look into it quickly. Please don’t access other people’s data or disrupt the service while testing.
Email a security reportsupport@brandmatchco.com