Security
How we handle your store's data.
The short version: encrypted, EU-hosted where we can be, and no listing ships without your review.
Overview
Listly processes product photos and text you upload, uses them to generate listings, and stores the results against your account. We minimise what we keep, encrypt what we do keep, and give you deletion on request. Nothing you upload is used to train third-party models.
Encryption
All traffic between your browser and Listly is served over TLS 1.2+. Data at rest — database rows, uploaded images, generated listings — is encrypted using AES-256 through our managed database and storage providers.
Access controls
Production access is restricted to the founding team, protected by SSO with mandatory two-factor authentication. Access is logged. We follow least-privilege: engineers get read-only access by default and elevated access only for a specific task.
Sub-processors
We use a small, deliberate set of providers to run Listly. Each is covered by our DPA.
Backups
The database is backed up daily with point-in-time recovery for the last 7 days. Backups are encrypted and stored in the same EU region as the primary database.
Vulnerability reporting
Found something? Email contact@listly.business with the subject line "SECURITY". Please give us a reasonable window to fix before public disclosure. We do not currently run a paid bounty programme but we do credit responsible reporters on request.
Incident response
We commit to assessing any reported or detected security incident within 24 hours, and to notifying affected customers without undue delay once the scope is understood. Post-incident write-ups are shared with affected customers.
Certifications
SOC 2 and ISO 27001 are on our roadmap and are not currently held. We won't claim badges we haven't earned.