Security

Rules, data and AI boundaries stay visible.

Sellentum is built on a simple safety principle: product selection stays deterministic and server-side, AI only explains selected product facts, and public widgets never receive dashboard secrets.

Authentication

Merchant access uses authenticated email and password sign-in with protected dashboard routes.

Database boundaries

Workspace data is isolated with row-level security policies and server-side routes for public runtimes.

Public runtime safety

Embedded experiences load published data server-side and return shopper-safe payloads instead of raw merchant logic.

Operational checks

Production verification, data-contract checks and runtime operations help prove launch readiness before traffic scales.

Responsible disclosure

If you believe you have found a security issue, email a clear report with affected URLs, reproduction steps and impact. Please report privately and give us a reasonable chance to fix it first — do not post exploit details, proof-of-concept code or affected data publicly. Our machine-readable contact is at /.well-known/security.txt.

Report an issue

Roadmap

Enterprise controls, in sequence.

Controls such as SSO, advanced audit logs, granular team permissions and formal compliance reports are on the roadmap. They are added once the core guided-selling workflow is production-proven, so the foundation stays solid first.

How selection stays deterministic