Skip to content

Security and privacy boundaries

Trust is a control system, not a badge strip.

Wand separates merchant, affiliate, internal administration, and public API authentication; scopes tenant data by trusted shop identity; and preserves audit and retry controls around sensitive workflows.

Tenant isolation

Tenant data queries and mutations are scoped by trusted shop identity, never a client ownership claim.

Authentication surfaces

Merchant admin, affiliate portal, super-admin, and public API boundaries remain separate.

Retry safety

Webhooks, jobs, commission writes, migrations, and payout operations preserve idempotency constraints.

Auditability

Sensitive status, payout, profile, tax, and administrative changes use established audit paths.

Data minimization

Public content and synthetic tours contain no production customer data, credentials, tax data, or payout configuration.

Evidence status

A control is not described as certified, production-proven, or approved without exact retained evidence.

See whether Wand fits your program.

Walk through the current product, evidence status, and launch boundaries with the team.

Book a walkthrough
Message Wand

Founder-led contact

How can we help?

Choose a private path. This is not a live-chat claim, and no third-party chat script loads here.

Send a messageBook a walkthrough