Launch offer — 0% transaction fees on your first 3 months

Trust & security

Your store runs on shared infrastructure, so we treat security as a platform-level responsibility — and we tell you plainly what we do and what we do not.

Encrypted in transit

  • All traffic is served over HTTPS with modern TLS. Plain HTTP requests are redirected, never served.
  • Certificates are issued and renewed automatically, so a store cannot silently drift into an expired-certificate state.
  • HSTS is enabled to prevent downgrade attempts on repeat visits.

How payments are handled

  • Card data is captured and processed by third-party payment providers, not stored on YouDuShop infrastructure. We never hold full card numbers or CVV codes.
  • Payment processing, fraud screening and chargeback handling are performed by those providers under their own compliance programmes (such as PCI DSS).
  • Which methods are available to you depends on your business entity, country and the provider's own review — we do not override their decisions.

Infrastructure and access control

  • Production servers run a minimal software footprint: only the components needed to serve the platform.
  • Administrative access is restricted to a small number of authorised engineers, using key-based authentication.
  • Access is granted on a least-privilege basis and reviewed as the team changes.

Network protection

  • Traffic is proxied through a global edge network with DDoS mitigation and web application firewall rules, which absorbs volumetric attacks before they reach the origin.
  • Your store's origin address is not exposed publicly, so attackers cannot target the server directly.
  • Abuse and anomalous traffic patterns are monitored and rate-limited.

Backups and resilience

  • Store and configuration data is backed up on a scheduled basis, with restore procedures tested rather than assumed.
  • Infrastructure is monitored for availability and performance, with alerting on abnormal conditions.
  • Platform components are kept up to date with security patches.

What is your responsibility

  • Keep your account credentials confidential and use a unique password.
  • Grant staff accounts only the access they actually need, and revoke access when people leave.
  • Comply with the laws that apply to what you sell and where you sell it.

Reporting a security issue

If you believe you have found a vulnerability in YouDuShop, contact us before disclosing it publicly. Include steps to reproduce and any relevant request details. We will acknowledge your report and keep you informed of the outcome.

Contact us

Questions about this page, or anything else — email us and we will get back to you.

[email protected]