TWAICY
Home/Trust & Security
Trusted Commerce Platform

Trust & Security

TWAICY is designed with a merchant-first architecture that prioritizes data ownership, direct payments, privacy, secure infrastructure, and transparent platform governance.

Security & Governance StatusActive Verified
100%
Merchant Data Ownership
0%
Platform Payment Holding
JWT
Secure Authentication
Multi-Tenant
Workspace Isolation
Direct Payouts
Merchant Controlled
Website Ownership
Always Yours

Trust & Security Guarantees

Merchant First Architecture

Merchant Owns Everything

Your products, customers, website, domain and branding always belong to you.

Direct Payment Architecture

Payments go directly to your configured merchant payment method without platform holding.

Secure Authentication

JWT authentication with strict role-based access control (RBAC) safeguards store staff.

Website Version Protection

Automatic layout snapshots and rollback protection before every live store deployment.

Multi-Tenant Workspace Isolation

Every merchant database workspace and storefront session is completely isolated.

Transparent Platform Governance

No hidden ownership, zero payment commissions, and no marketplace vendor lock-in.

1. Overview

Why TWAICY Exists & Our Merchant-First Mission

TWAICY was founded with a singular conviction: Local merchants and modern businesses deserve complete control over their digital commerce ecosystem.

Traditional e-commerce aggregators and platforms often impose hidden lock-ins, hold merchant revenue in central platform wallets for settlement days, or retain control over customer data. TWAICY operates under a strictly merchant-first architecture.

Merchant-First Platform

Every feature—from catalog management to website building—is designed to empower merchants without imposing arbitrary platform commissions or restrictions.

No Hidden Ownership

We do not claim ownership of your customer lists, catalog metadata, or store branding. Your business data remains 100% your asset.

Pure Technology Partner

TWAICY acts as your software engine. We do not compete with your business, run marketplace algorithms against your products, or promote competitors.

Transparent Governance

Clear API documentation, open integrations, and honest compliance reporting form the bedrock of our software delivery.

2. Merchant Data Ownership

Full Data Sovereignty & Zero Platform Claims

TWAICY operates on the principle that your business data belongs strictly to you. We provide the software platform infrastructure, but do not claim ownership rights over your products, customers, pricing, or commerce intelligence.

Products belong to merchant

Catalog items, pricing rules, media galleries, and SKUs.

Customers belong to merchant

Customer profiles, contact records, and order history.

Inventory belongs to merchant

Stock ledger records, warehouse counts, and supply metadata.

Orders belong to merchant

Sales transactions, invoice records, and revenue details.

Website belongs to merchant

Storefront layouts, section designs, and published domain pages.

Branding belongs to merchant

Store logos, color themes, domain identity, and trademarks.

Zero Lock-In Commitment: Merchant data is stored securely in structured database formats. Full data export options for products, orders, and customer lists are accessible to store owners anytime.

3. Payments & Direct Settlements

Direct Settlement Architecture — Zero Platform Holding Wallet

TWAICY does not hold or collect merchant funds in platform escrow wallets. The architecture is engineered so payments go directly to the merchant's configured payment channel.

Direct Payment Settlement Flow
01

Customer

Places storefront order

02

Merchant Payment Gateway

Razorpay / UPI QR / COD

03

Merchant Bank Account

100% Direct Payout

Merchant UPI QR

Instant customer UPI transfers into merchant bank account.

Razorpay API Keys

Enter your own Razorpay key ID & secret for direct card/netbanking payouts.

Cash on Delivery

Cash collected directly at doorstep upon order fulfillment.

4. Privacy & Data Governance

Minimal Data Minimization & Confidentiality Safeguards

TWAICY adheres to strict data minimization principles. We only collect and store data that is operationalized for running your online store, catalog, and order fulfillment.

Operational Data Storage

Only information required to process catalog items, website pages, and order invoices is stored.

Credential Protection

Passwords are cryptographically hashed before database persistence. Plaintext passcodes are never saved.

Isolated Merchant Data

Customer metadata is scoped strictly to your store ID. Cross-tenant customer visibility is blocked.

No Unnecessary PII Collection

We do not track unnecessary personal identification metrics or resell user activity logs.

Honest Security & Compliance Disclosure
HTTPS / TLS Ready
JWT Authentication
Role-Based Access
Store Isolation
Soft Delete Archival
System Audit Logging

Note: TWAICY is engineered with modern security engineering best practices. We do not claim SOC2, ISO 27001, PCI DSS, GDPR, or HIPAA certifications until formal third-party audits are completed.

5. Platform Security Controls

Technical Safeguards Protecting Platform & Workspace Integrity

JWT Authentication

Signed stateless tokens for verified user login sessions.

Role Based Access (RBAC)

Scoped permissions for Merchant Owners, Staff, and Admins.

Store Workspace Isolation

Schema boundary segregation preventing cross-tenant access.

Website Version Snapshots

Immutable layout state snapshots created on every publish.

Deployment Audit Logs

Historical records of publish timestamps, authors, and CDN purges.

System Audit Logs

Tracking critical store settings, role changes, and key edits.

1-Click Version Rollback

Instant restoration to any previous working website snapshot.

Private Draft Preview

Signed preview URLs protect draft edits from public view.

Background Autosave

30-second background autosaving keeps canvas edits safe.

6. Website Security & Publishing Pipeline

Stage-by-Stage Publishing Architecture & Version Safeguards

The TWAICY Website Builder is engineered with a strict 4-stage deployment pipeline to ensure unsaved edits never break your active online storefront.

01
Isolated

Draft Canvas State

Make changes to theme tokens, sections, and navigation. Canvas edits stay in draft mode and are never visible on your live storefront.

02
Protected

Private Signed Preview

Generate short-lived signed JWT preview links. Share with team members to preview exact mobile/desktop renders prior to publishing.

03
Validated

Publish Validation Check

Automated engine validates missing links, draft blocks, and SEO metadata. Creates an immutable version snapshot backup.

04
HTTPS Live

Live Storefront Sync

One-click deployment pushes changes to the live storefront and purges CDN edge cache instantly. 1-click rollback available anytime.

1-Click Instant Rollback: Every deployment creates an immutable layout snapshot. If a mistake occurs, restore any previous working layout in seconds.
HTTPS Enforced: All live storefront websites are designed to support SSL/TLS encryption for end-to-end transport security.

7. Shipping Integrations

Merchant Courier Credentials & Direct Account Connections

Merchants link their own official courier accounts. TWAICY never owns, holds, or manages merchant courier credentials or freight wallet balances.

SHIPROCKET

Shiprocket Integration

Connect your own Shiprocket API secret keys for automated AWB generation, label printing, and tracking.

DELHIVERY

Delhivery Direct

Direct B2C courier API dispatch through your official merchant account.

FLEET

Self Delivery / Local Fleet

Manage your own local store drivers, custom radius fees, and doorstep cash collection.

8. Platform Architecture Flow

End-to-End Commerce Operational Flow

The TWAICY Commerce OS connects merchant workspace controls, website publishing, real-time inventory ledgers, direct payment channels, and courier APIs into an integrated workflow.

STAGE 01

Merchant

Authenticated Workspace Owner

STAGE 02

Website Builder

JSON Canvas Engine & Themes

STAGE 03

Orders

Real-Time Ledger & Inventory

STAGE 04

Payments

Direct Settlement Gateway

STAGE 05

Shipping

Merchant Courier Dispatch

STAGE 06

Customers

Fulfillment & Retention

9. Frequently Asked Questions

Common Merchant Trust & Security Inquiries

No. TWAICY does not collect or hold merchant funds in platform wallets. Payments are collected directly through your configured merchant payment channels (such as your own Razorpay account, direct bank UPI QR, or Cash on Delivery). Funds land straight into your bank account with zero middleman settlement delays.

10. Contact Security & Support

Security Vulnerabilities & Platform Technical Assistance

We take platform security, merchant data privacy, and responsible vulnerability disclosures seriously. Reach out directly to our engineering desks.

Security Vulnerabilities
security@twaicy.com

For vulnerability reports & security research disclosure.

General Platform Support
support@twaicy.com

For merchant onboarding, store assistance & billing help.

Sovereign Commerce OS

Build your business with confidence.

Own your customers, receive payments directly, manage your website, and grow with a merchant-first Commerce OS.

HomeSearchProfile