EMPIRE / Security

How your site and your customers' data are protected.

Plain descriptions of what is actually in place, and what isn't. If you need something specific for a compliance review, call us and we'll answer directly.

A phone, camera and notebook on a dark desk
A small product set lit in a darkened studio

TLS on every site

SSL certificates are issued, installed, and renewed automatically for every domain on every plan. Nothing to buy or configure.

DDoS mitigation

Sites sit behind an enterprise mitigation layer that absorbs volumetric attacks before they ever reach your store.

We never touch card data

Card details go directly to Stripe, a PCI Level 1 certified processor. They never pass through EMPIRE's systems.

Hosting & network

EMPIRE runs on an enterprise global edge platform. Your pages are served from data centres worldwide rather than a single origin server, which means faster loads and no single machine to knock over.

Traffic is encrypted end to end, and HTTPS is enforced — visitors arriving over plain HTTP are upgraded automatically.

Payment security

All card processing is handled by Stripe. When a customer checks out, their card details are submitted directly to Stripe's systems. CryptCode never receives, stores, or transmits card numbers, CVCs, or full payment credentials.

Funds settle from Stripe to your bank account. We are not in the money flow and cannot hold, freeze, or withdraw your revenue.

What data we store

We store what's needed to run your site and nothing beyond it:

  • Your account email, domain, plan, and access code.
  • Your site's content — text, settings, uploaded images, products.
  • Order records: buyer email, amount, item summary, and status.
  • Aggregate page-view and click counts per day.
  • Messages submitted through your contact or order forms.

See the privacy policy for how this is handled and how to request deletion.

Account access

Dashboard access uses an access code issued when your site is provisioned. Treat it like a password: don't share it, and tell us immediately if you think it's been exposed so we can rotate it.

What we don't offer

Being straight about the boundaries:

  • We are not currently SOC 2 or ISO 27001 certified.
  • We do not offer HIPAA compliance and EMPIRE should not be used to store protected health information.
  • We do not currently offer two-factor authentication on dashboard login. It's on the roadmap.
  • We do not offer a contractual uptime SLA with financial credits.

If any of those are requirements for you, a larger platform is the honest recommendation.

Reporting a security issue

Found something? Email [email protected] with the subject line SECURITY, or call 402-206-4827. We'd rather hear it from you than from an attacker, and we won't be difficult about it.