Skip to content
Open menu

Control by design

Security follows the operating boundary.

Pexify separates public, seller, supply, and admin concerns while keeping marketplace access explicit and purpose-limited.

Separated operating zones connected through deliberate access gates

Security posture

Practical controls across the platform.

Transport security

Pexify web origins use TLS for data in transit.

Credential protection

Marketplace credentials are encrypted at rest and authorization uses marketplace OAuth flows.

Least privilege

Roles and capabilities constrain which actors can reach sensitive workflows.

Tenant isolation

Organization context and permission checks keep tenant data separated.

Origin separation

Public, app, and admin surfaces use separated origins and responsibilities.

Monitoring and recovery

Operational monitoring, backups, offsite WORM copies, and restore drills support recoverability.

Seller control

Authorization can be granted and revoked.

Connecting a marketplace does not hand Pexify an unlimited mandate. The seller controls the connection, while Pexify limits use to supported workflows.

Security questions

Does Pexify ask for marketplace passwords?

Marketplace integrations use their authorization flows rather than collecting marketplace passwords.

Can every user access admin data?

No. Admin capabilities and origins are separated from seller and supply experiences.

How do I report a security concern?

Use the contact page or email hello@pexify.net with enough detail for the team to investigate.

Need to understand how your data is handled?