Your data, secure by default.
AES-256-GCM encrypted secrets, append-only audit trail, security gates on every push and round-the-clock monitoring. Security is the foundation of Daras, not an add-on; independent audit, penetration testing and field-level encryption of customer data are on our roadmap.
Certification path,
Documents will be shared on this page as certification processes complete. We provide security documentation on request under a confidentiality agreement.
Our information security management system is built to ISO 27001 requirements; independent certification is on our roadmap.
Processes and controls are designed around SOC 2 principles; an independent Type II audit is planned.
Card data never touches Daras infrastructure; payments are tokenized and processed through payment-security certified payment institutions.
KVKK compliance is actively maintained: data processing inventory, disclosure notices and a data-subject request channel are in place.
Infrastructure,
The Daras security model rests on three pillars — each pillar is validated by an independent audit and evidence.
- Data centresGermany (EU)
- Cloud providerServers located in Türkiye
- Secret encryptionAES-256-GCM
- In transitTLS 1.3 only
- Backup3× / 4 hours
- Disaster recoveryRedundant
- SSOSAML 2.0 / OIDC
- Two-factorTOTP (team) · passkey (customers)
- RBACGranular + IP fence
- AuditFull · immutable
- Data export48 hours
- Role-based accessActive
- Status transparencyLive page
- Service termsBy contract
- Data ownershipCustomer
- DPAStandard included
- Response timeTarget by severity
- MSATurkish / English
Questions your
The 8 questions we receive most often in RFPs. For deeper technical questions, write to security@platform.contactEmailDomain.
Try it in your trial store, go live when you are ready.
The migration team moves your products, customers, orders and theme; a 301 redirect map keeps your SEO intact.