Trust center

Security and data boundaries

A concise view of how Muvexa protects store credentials and limits retained API data.

Credentials

Marketplace refresh tokens are encrypted at rest. Store API keys are scoped to a platform and authorized store.

Request logs

Logs retain operational metadata such as method, path, platform, status and latency. Request and response bodies are not retained by default.

Tenant isolation

Authorization mappings, API keys and usage records belong to a tenant. Backend authorization must enforce tenant and role boundaries.

Report a security issue

Send responsible security reports to [email protected]. Include affected endpoint, reproduction details and impact without sending live credentials.