Sellentum is in testing. Please do not buy a paid plan yet.Ask about the pilot

Security

Rules, data and AI boundaries stay visible.

Sellentum is built on a simple safety principle: product selection stays deterministic and server-side, AI only explains selected product facts, and public widgets never receive dashboard secrets.

Authentication

Merchant access uses authenticated email and password sign-in with protected dashboard routes.

Database boundaries

Workspace data is isolated with row-level security policies and server-side routes for public runtimes.

Public runtime safety

Embedded experiences load published data server-side and return shopper-safe payloads instead of raw merchant logic.

Operational checks

Production verification, data-contract checks and runtime operations help prove launch readiness before traffic scales.

Data we receive

Exactly what comes to us, and what never does.

This list is checked against our code by an automated test, so it cannot quietly go out of date. The same list is available as data at /api/v1/data-manifest.

What shoppers do in your store

From: Shoppers' browsers, through the Sellentum search, finder or assistant on your store

We receive

  • Search words, questions and answers a shopper chooses, with emails, phone numbers and card numbers removed before storage
  • Which products were shown, and which buy buttons were clicked
  • A random session id that is not linked to a person

We never receive

  • Shopper names, email addresses, phone numbers or payment card numbers
  • Shopper IP addresses are not stored: only a secret-keyed one-way code is kept, to stop abuse
  • Your orders or your customer records

Why: Choose and explain products, and show you reports on what shoppers look for

How long: Kept while your account exists and deleted with it. Search caches keep only a one-way code of the words and are not used after 7 days. Abuse counters reset within a day.

Your product catalog

From: You: store sync, product feeds, file uploads, manuals and your own edits

We receive

  • Product names, descriptions, prices, stock, images, categories, tags and variants
  • Product manuals and answers you give about your products
  • Facts and descriptions Sellentum writes from your product text, with the source kept

We never receive

  • Orders, customers or payment details from your store platform

Why: Understand your products so rules can choose them and AI can explain them

How long: Kept while your account exists and deleted with it. Your original product text is kept beside anything Sellentum adds.

The connection to your store platform

From: Your store platform, after you approve the connection

We receive

  • Your shop address and the access key you approve
  • Notices that products changed, which trigger a sync

We never receive

  • The content of those notices: only a one-way code of each notice is kept, to avoid doing the work twice

Why: Keep your catalog in step with your store

How long: Kept while the connection exists. Access keys are stored separately and never sent to a browser.

Your Sellentum account

From: You and your payment provider

We receive

  • Your name, email address and workspace settings
  • Your plan, usage counts and payment status notices
  • Your finders, searches, widget settings, API keys and report schedules
  • Messages you send to support

We never receive

  • Your full payment card number: the payment provider holds it

Why: Run your account, bill correctly and answer you

How long: Kept while your account exists and deleted with it, except where the law requires billing records to be kept.

Keeping the service safe

From: Sellentum's own systems

We receive

  • Error and warning records, with secrets and personal details removed
  • A record of changes Sellentum administrators make to accounts

We never receive

  • Passwords, access keys or payment details in any record

Why: Find faults, stop abuse and keep an audit trail

How long: Kept while needed to run and secure the service.

Responsible disclosure

If you believe you have found a security issue, email a clear report with affected URLs, reproduction steps and impact. Please report privately and give us a reasonable chance to fix it first — do not post exploit details, proof-of-concept code or affected data publicly. Our machine-readable contact is at /.well-known/security.txt.

Report an issue

Roadmap

Enterprise controls, in sequence.

Controls such as SSO, advanced audit logs, granular team permissions and formal compliance reports are on the roadmap. They are added once the core guided-selling workflow is production-proven, so the foundation stays solid first.

How selection stays deterministic