Security & Auditing
Enterprise-grade security features to protect your data and track every administrative action within your engine.
Infrastructure Security
Ecomentic is built with a security-first architecture, ensuring that your tenant data is logically and physically isolated.
- Data Isolation: Each tenant operates in its own PostgreSQL schema or a dedicated database instance (Business Plan).
- Magic Link Auth: Secure, passwordless login for administrators to prevent credential theft.
- API Security: Scoped Personal Access Tokens with granular permissions for external integrations.
Administrative Auditing
Keep a complete trail of who did what and when. The Audit Log captures all critical changes to products, orders, and system settings.
How to View Audit Logs
- Navigate to Settings > System > Audit Logs.
- Filter by User, Action Type, or Date Range.
- Click on any log entry to see the "Before" and "After" state of the data.
Role-Based Access Control (RBAC)
Define custom roles with specific permissions. Ensure your staff only has access to the modules they need to perform their jobs. This prevents unauthorized access to sensitive financial data or system configurations.
Security Best Practice
Always enable Two-Factor Authentication (2FA) for all administrative accounts to ensure maximum protection against unauthorized access.
For emergency key rotation and proxy secret updates, refer to the Security SOP Key Rotation Guide.