BANK-GRADE PROTECTION & 2FA
Security & Enterprise Architecture
Sellora employs a multi-layered, defense-in-depth security architecture to ensure your online store runs autonomously without vulnerability or interruption.
### 1. Mandatory Server-Side 2FA Enforcement
All administrative login sessions, team member invitations, and role-based access control (RBAC) modifications are protected by mandatory server-side Two-Factor Authentication (TOTP/2FA), preventing credential stuffing and unauthorized account takeover.
### 2. Cryptographic Webhook Replay Protection
Incoming financial webhooks and payment confirmations from Paymob, InstaPay Egypt, Fawry, and Shopify are rigorously validated using HMAC SHA-256 cryptographic signatures combined with timestamp replay protection to prevent spoofing or fraudulent order confirmations.
### 3. Immutable Security Audit Logging
Every critical workspace action—including price adjustments, inventory overrides, manual order creations, and team member permission changes—is permanently recorded in an immutable security audit log available for your inspection.