Security, by default.
KVKK-compliant data processing; independent ISO/SOC 2 audits are on our roadmap. Card data is not stored at Daras (payments are processed by payment-security certified payment institutions), customer data is stored in the EU (Germany), and every admin action goes to an append-only log.
Certified, audited, transparent security.
4 certifications
KVKK-compliant data processing; payments via certified payment institutions; independent ISO/SOC 2 audits on the roadmap.
KVKK + data residency
Customer data is stored in the EU (Germany); each store's data is isolated.
Certified card vault
Card data is not stored at Daras; a saved card is kept as a token at the payment institution.
Append-only audit log Kurumsal and up
Every admin action, login, role change, refund — recorded immutably.
How data access is governed.
SSO + 2FA
Office 365 / Google Workspace SSO via SAML; authenticator-app 2FA (TOTP) for your team, passkeys for customers.
Role-based permissions
Fine-grained permissions: subject + action + condition; team roles are limited to catalog, orders, marketing, content and accounting areas.
Audit
Every read/write + IP + user-agent recorded append-only.
Encryption
TLS 1.3 in transit; payment and integration secrets encrypted with AES-256-GCM; backups encrypted before transfer.
Pen-test
Penetration testing and independent audits are on our roadmap; security gates run on every push.
Incident response
A defined incident response process; KVKK requires breach notification within 72 hours.
In security, the details we care about.
Customer and order data in a data centre in Germany (EU); isolation between stores is enforced by the architecture.
Card numbers are not stored at Daras and never written to logs; they are tokenized at the payment institution.
Office 365, Google Workspace, Okta, Azure AD via SAML 2.0; TOTP 2FA for the team, passkeys for customers.
Permission check and store scope guard on every endpoint.
UPDATE+DELETE revoked at the DB role level; audit-ready.
Traffic encrypted end to end, secrets encrypted at the application layer, passwords stored irreversibly.
KVKK-mandated 72-hour breach notification; a defined incident-response and root-cause process.
Security, protects which modules.
Available on
Try it in your trial store, go live when you are ready.
The migration team moves your products, customers, orders and theme; a 301 redirect map keeps your SEO intact.