Legal

Security Practices

At Squid Support, we take the security of your data seriously. We implement robust technical and organizational measures to ensure the confidentiality, integrity, and availability of our services and your data.

Data Encryption

All data transmitted between your clients and our servers is encrypted using industry-standard TLS (Transport Layer Security). Data at rest is encrypted using AES-256 encryption.

Access Control

Access to our infrastructure and customer data is strictly limited to authorized personnel on a need-to-know basis. We enforce multi-factor authentication (MFA) and strong password policies for all administrative access.

Vulnerability Management

We continuously monitor our infrastructure for potential vulnerabilities. As part of our secure development lifecycle, we conduct regular dependency audits and employ static and dynamic code analysis tools.

Compliance

Our security processes are designed to align with strict industry standards and European data protection requirements (GDPR), ensuring that your e-commerce helpdesk operations remain secure and legally compliant.

Backups and Recovery

Production databases are backed up automatically every day and retained for 30 days. Backups are encrypted at rest and held in the same EU region as the live database. Before any destructive remediation during an incident, we take an on-demand backup so the affected state is preserved.

Incident Response

We maintain a documented incident response policy covering severity classification, containment, evidence preservation, and our notification commitments — including notifying affected merchants within 72 hours and the competent supervisory authority under GDPR Art. 33 where required. Read the full Security Incident Response Policy.

Reporting a Security Issue

If you believe you have discovered a vulnerability in our services, please report it to us immediately at legal@squidsupport.ai. We request that you do not publicly disclose the issue until we have had an opportunity to address it. We acknowledge security reports within 24 hours.