Trust & security
You are hiring us to protect you. Here is exactly how the thing is put together, including where it deliberately does less than a competitor would claim.
Last updated 17 August 2026
We are never in your traffic path
The protection core runs inside your own system and decides locally. Nothing your visitors do has to travel through us first. If our infrastructure disappears entirely, your site keeps running and keeps being protected — it simply stops sending us signals until we are back.
Fail-safe by default
When the core cannot reach us, it does not panic and it does not open the gates. It keeps enforcing the last policy it holds, keeps its own judgment running, and queues what it wanted to tell us. This behaviour is shipped in the core itself, not configured on our side.
Signed updates
Every release is signed with our Ed25519 release key and verified before it is accepted. The public key is published at /api/public/release-key so you can check a release yourself. Critical releases carry a deadline; after it, an out-of-date install is told to upgrade rather than silently drifting.
Your panel is yours
What you see in your account is your own system, and only your own system. There is no cross-customer view on your side. Our internal operations console is separate, closed, and not reachable from a customer account — so one compromised login cannot become everyone's problem.
Access control
- Every table is protected at the database level, not just in the app.
- Privileged routines run as security-definer functions in a private schema that nobody can call directly.
- Staff roles are granted and revoked in the database with an append-only audit trail.
- The company cannot lock itself out: the last founder role cannot be removed.
Data minimisation
We collect security signals, not your business data. No customer records, no order contents, no card data. The identity layer is built so that we cannot link a person to a shop even if we wanted to. See the privacy notice for the full list.
What we do not claim
- No certification badges we have not earned.
- No response-time or uptime SLA we cannot honestly keep — support is AI-first and always on instead.
- No promise that nothing will ever happen. Anyone promising that is selling you a feeling.
Reporting a vulnerability
If you find a weakness in isharpai, tell us through the assistant in any account — including a free one — and mark it as a security report. We will not take legal action against good-faith research that does not degrade the service or touch other customers' data.
Questions about this page? Ask the assistant inside your account, or open a ticket there — it reaches us directly.