Security

Built secure.

Plain words about how we protect your website, your store and your customers. We only list what is actually in place today.

What protects you

Locked connection, everywhere

Every Wannlabs page and app (wannlabs.com, Ember, OpenSign and Prime) only loads over HTTPS, so what you type travels encrypted.

One careful sign-in

One Wannlabs account works across our apps. New accounts confirm their email first, and sign-ups are checked for throwaway emails and too many attempts.

Your data stays yours

In Ember Cloud, each app’s data is locked so every person can only see and change their own rows. The database itself enforces this, not just the app.

Encrypted when stored

Prime messages and files, and data saved in Ember Cloud, are encrypted when stored, with a separate key for each account or project.

Extra encryption in Prime

Prime, our assistant for mortgage brokers, adds its own layer of encryption to messages between your browser and our servers, on top of HTTPS.

Payments by Stripe

You pay on Stripe’s secure checkout page. Your card number goes to Stripe and never touches our servers.

Fair limits, enforced

Plan limits and AI points are checked on our servers, so nobody can get around them from their browser.

Screening for abuse

Ember checks requests, code and published sites for scams, malware and illegal content. Accounts that keep trying get paused for review.

AI asks before risky changes

Before Ember makes a big or risky change (like touching sign-in, payments or your data) it tells you and waits for your OK. Prime waits for your approval before sending anything.

Admin access is logged

Sensitive admin actions, like an admin viewing an account for support, are recorded in an audit log.

Google access, carefully

Connecting your Google account is in early access: we turn it on account by account, and you can disconnect it any time from your dashboard.

Nightly backups

Our account and app databases are backed up every night to a separate disk, so we can recover from mistakes or hardware trouble.

What we don’t claim

We don’t hold security certifications like SOC 2, HIPAA or PCI today, and we won’t say we do. Card payments are handled by Stripe. No system is perfect, so we keep improving and we want to hear about problems.

Report a security issue

Found something that looks wrong? Email us and we’ll look into it quickly. Please don’t access other people’s data or disrupt the service while testing.

Email a security report

support@brandmatchco.com