Skip to content
CIQRA
Trust

Enterprise-grade security, as the default

Multi-tenant is only safe if isolation is real. CIQRA treats isolation, encryption and residency as core infrastructure — so trust isn't a paid add-on.

100%EU-hosted & GDPR-native
0Card data stored (PCI SAQ A)
Isolation you can point to

One platform, every store walled off

Each store's data is scoped by row-level security in PostgreSQL — the database itself refuses to return another tenant's rows, even if application code slips.

  • tenant_id enforced at the database layer
  • Verified by a leak-test suite in CI
  • Per-tenant encryption keys
One database, isolated per store
acme-store RLS scoped
nimbus-co RLS scoped
aurora-goods RLS scoped
Enforced at the database, not just the app
Security posture

Trust, built into the platform

Tenant isolation

PostgreSQL row-level security scopes every query to one store — at the database, not just the app.

Field-level encryption

Sensitive fields encrypted with per-tenant keys wrapped by a hardware-backed key vault.

EU data residency

Hosted on Azure in Germany (Frankfurt), with disaster recovery in Germany North.

PCI DSS SAQ A

Card data is tokenised by the processor and never touches CIQRA servers.

GDPR-native

Consent-aware analytics, data-subject rights and a published subprocessor list.

Cross-tenant leak tests

An isolation suite gates every merge, so one store's data can't reach another.

Secrets in Key Vault

Secrets and encryption keys are managed in Azure Key Vault with rotation.

Modern auth

OpenID Connect with auth-code + PKCE and MFA, and tenant-scoped role-based access.

FAQ

Frequently asked questions

Start building on CIQRA

Spin up a store in minutes. Bring your own gateway or turn on CIQRA Pay — your data stays in the EU.