---
title: "Security — Daras"
canonical_url: "https://daras.com.tr/en/platform/security"
last_updated: "2026-10-07T09:15:02.458Z"
locale: en
meta:
  description: "KVKK-compliant data processing, append-only audit logging, TLS 1.3 and data stored in the EU (Germany); independent ISO/SOC 2 audits on the roadmap."
  "og:description": "KVKK-compliant data processing, append-only audit logging, TLS 1.3 and data stored in the EU (Germany); independent ISO/SOC 2 audits on the roadmap."
  "og:title": "Security — Daras"
  "twitter:description": "KVKK-compliant data processing, append-only audit logging, TLS 1.3 and data stored in the EU (Germany); independent ISO/SOC 2 audits on the roadmap."
  "twitter:title": "Security — Daras"
---

Platform · Security 14

# **Security, **by default.

KVKK-compliant data processing; independent ISO/SOC 2 audits are on our roadmap. Card data is not stored at Daras (payments are processed by payment-security certified payment institutions), customer data is stored in the EU (Germany), and every admin action goes to an append-only log.

[Book a demo ](https://daras.com.tr/demo) [Open a trial store](https://app.daras.com.tr/register)

**Encrypted transport**

**Encrypted end to end**

HSTS + strict CSP

**80+**

**CI quality and security gates**

Run on every push

**Certified payments**

**L1 payment institutions**

Card data is not stored with us

**KVKK**

**\+ GDPR**

Data in the EU (Germany)

What it does

## Certified, audited, *transparent security.*

### **4 certifications **

KVKK-compliant data processing; payments via certified payment institutions; independent ISO/SOC 2 audits on the roadmap.

### **KVKK + data residency **

Customer data is stored in the EU (Germany); each store's data is isolated.

### **Certified card vault **

Card data is not stored at Daras; a saved card is kept as a token at the payment institution.

### **Append-only audit log **Kurumsal and up

Every admin action, login, role change, refund — recorded immutably.

How it works in Daras

## How data access *is governed.*

**Step 01**

### **SSO + 2FA**

Office 365 / Google Workspace SSO via SAML; authenticator-app 2FA (TOTP) for your team, passkeys for customers.

**Step 02**

### **Role-based permissions**

Fine-grained permissions: subject + action + condition; team roles are limited to catalog, orders, marketing, content and accounting areas.

**Step 03**

### **Audit**

Every read/write + IP + user-agent recorded append-only.

**Step 04**

### **Encryption**

TLS 1.3 in transit; payment and integration secrets encrypted with AES-256-GCM; backups encrypted before transfer.

**Step 05**

### **Pen-test**

Penetration testing and independent audits are on our roadmap; security gates run on every push.

**Step 06**

### **Incident response**

A defined incident response process; KVKK requires breach notification within 72 hours.

Feature details

## In security, *the details we care about.*

**Turkey data residency **

Customer and order data in a data centre in Germany (EU); isolation between stores is enforced by the architecture.

**Certified payment institutions **

Card numbers are not stored at Daras and never written to logs; they are tokenized at the payment institution.

**SSO + 2FA **Kurumsal and up

Office 365, Google Workspace, Okta, Azure AD via SAML 2.0; TOTP 2FA for the team, passkeys for customers.

**Role-based permissions **

Permission check and store scope guard on every endpoint.

**Append-only log **Kurumsal and up

UPDATE+DELETE revoked at the DB role level; audit-ready.

**Encryption **

Traffic encrypted end to end, secrets encrypted at the application layer, passwords stored irreversibly.

**Incident response **

KVKK-mandated 72-hour breach notification; a defined incident-response and root-cause process.

Works with these modules

## Security, *protects which modules.*

[<h3>**Orders**</h3>

Append-only order status log + fraud detection.**Open module **](https://daras.com.tr/en/platform/orders)

[<h3>**Payments**</h3>

Certified card vault + 3DS + provider fraud rules.**Open module **](https://daras.com.tr/en/platform/payments)

[<h3>**API**</h3>

Scope + rate limit + audit log + secret rotation.**Open module **](https://daras.com.tr/en/platform/api)

[<h3>**Checkout**</h3>

3DS + risk score + marketing consent.**Open module **](https://daras.com.tr/en/platform/checkout)

Plan coverage

### **Available on**

**Dükkân**** Kervan**** Han**** Enterprise (SSO/SAML)**

[**See all plan details **](https://daras.com.tr/en/pricing)

Get started

## **Try it in your trial store, go live when you are ready.**

The migration team moves your products, customers, orders and theme; a 301 redirect map keeps your SEO intact.

[**Start free**](https://app.daras.com.tr/register) [**Developer portal**](https://developers.daras.com.tr/docs)