Security at techtone.ai
Your data security is our top priority. Learn about the measures we take to protect your information.
Encryption
All data is encrypted in transit using TLS/SSL and at rest using AES-256 encryption.
Secure Infrastructure
Hosted on Google Cloud Platform and Supabase with enterprise-grade security.
Access Controls
Row-Level Security policies ensure users can only access their own data.
Secure Authentication
Password hashing with bcrypt and OAuth 2.0 support for third-party logins.
Our Security Practices
At techtone.ai, we implement industry-standard security measures to protect your data and ensure the integrity of our platform.
Data Protection
✓ Encryption at Rest
All stored data is encrypted using AES-256 encryption, including your Shopify theme files, brand assets, and chat history.
✓ Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security).
✓ Shopify OAuth Tokens
Your Shopify store access tokens are encrypted before storage and are never exposed in logs or external systems.
Infrastructure Security
Our infrastructure is built on trusted, enterprise-grade platforms:
- Google Cloud Platform: AI processing (Vertex AI) and cloud infrastructure
- Supabase: Database hosting with built-in security features and Row-Level Security (RLS)
- Vercel: Frontend hosting with automatic HTTPS and DDoS protection
All our infrastructure providers maintain industry certifications and compliance standards.
Access & Authentication
We implement multiple layers of access control:
- Password Security: All passwords are hashed using bcrypt with individual salts
- Row-Level Security: Database policies ensure users can only access their own data
- API Authentication: Secure service role keys and authentication tokens
- Session Management: Secure session cookies with HttpOnly and SameSite flags
Regular Security Audits
We continuously monitor and improve our security posture through:
- Regular security assessments and vulnerability scanning
- Automated dependency updates to patch known vulnerabilities
- Code reviews with security best practices in mind
- Monitoring and alerting for suspicious activity
Your Responsibilities
While we work hard to protect your data, security is a shared responsibility:
- Use a strong, unique password for your account
- Never share your account credentials
- Log out from shared or public devices
- Review AI-generated code before deploying to your live store
- Keep backups of your Shopify theme
- Report any security concerns to security@techtone.ai
Reporting Security Issues
If you discover a security vulnerability, please report it to us immediately at security@techtone.ai.
We take all security reports seriously and will investigate promptly. Please do not publicly disclose vulnerabilities until we have had a chance to address them.
Questions?
Have questions about our security practices? We're here to help.
