Trust & Security
TWAICY is designed with a merchant-first architecture that prioritizes data ownership, direct payments, privacy, secure infrastructure, and transparent platform governance.
Trust & Security Guarantees
Merchant First ArchitectureMerchant Owns Everything
Your products, customers, website, domain and branding always belong to you.
Direct Payment Architecture
Payments go directly to your configured merchant payment method without platform holding.
Secure Authentication
JWT authentication with strict role-based access control (RBAC) safeguards store staff.
Website Version Protection
Automatic layout snapshots and rollback protection before every live store deployment.
Multi-Tenant Workspace Isolation
Every merchant database workspace and storefront session is completely isolated.
Transparent Platform Governance
No hidden ownership, zero payment commissions, and no marketplace vendor lock-in.
1. Overview
Why TWAICY Exists & Our Merchant-First Mission
TWAICY was founded with a singular conviction: Local merchants and modern businesses deserve complete control over their digital commerce ecosystem.
Traditional e-commerce aggregators and platforms often impose hidden lock-ins, hold merchant revenue in central platform wallets for settlement days, or retain control over customer data. TWAICY operates under a strictly merchant-first architecture.
Merchant-First Platform
Every feature—from catalog management to website building—is designed to empower merchants without imposing arbitrary platform commissions or restrictions.
No Hidden Ownership
We do not claim ownership of your customer lists, catalog metadata, or store branding. Your business data remains 100% your asset.
Pure Technology Partner
TWAICY acts as your software engine. We do not compete with your business, run marketplace algorithms against your products, or promote competitors.
Transparent Governance
Clear API documentation, open integrations, and honest compliance reporting form the bedrock of our software delivery.
2. Merchant Data Ownership
Full Data Sovereignty & Zero Platform Claims
TWAICY operates on the principle that your business data belongs strictly to you. We provide the software platform infrastructure, but do not claim ownership rights over your products, customers, pricing, or commerce intelligence.
Products belong to merchant
Catalog items, pricing rules, media galleries, and SKUs.
Customers belong to merchant
Customer profiles, contact records, and order history.
Inventory belongs to merchant
Stock ledger records, warehouse counts, and supply metadata.
Orders belong to merchant
Sales transactions, invoice records, and revenue details.
Website belongs to merchant
Storefront layouts, section designs, and published domain pages.
Branding belongs to merchant
Store logos, color themes, domain identity, and trademarks.
3. Payments & Direct Settlements
Direct Settlement Architecture — Zero Platform Holding Wallet
TWAICY does not hold or collect merchant funds in platform escrow wallets. The architecture is engineered so payments go directly to the merchant's configured payment channel.
Customer
Places storefront order
Merchant Payment Gateway
Razorpay / UPI QR / COD
Merchant Bank Account
100% Direct Payout
Merchant UPI QR
Instant customer UPI transfers into merchant bank account.
Razorpay API Keys
Enter your own Razorpay key ID & secret for direct card/netbanking payouts.
Cash on Delivery
Cash collected directly at doorstep upon order fulfillment.
4. Privacy & Data Governance
Minimal Data Minimization & Confidentiality Safeguards
TWAICY adheres to strict data minimization principles. We only collect and store data that is operationalized for running your online store, catalog, and order fulfillment.
Operational Data Storage
Only information required to process catalog items, website pages, and order invoices is stored.
Credential Protection
Passwords are cryptographically hashed before database persistence. Plaintext passcodes are never saved.
Isolated Merchant Data
Customer metadata is scoped strictly to your store ID. Cross-tenant customer visibility is blocked.
No Unnecessary PII Collection
We do not track unnecessary personal identification metrics or resell user activity logs.
Note: TWAICY is engineered with modern security engineering best practices. We do not claim SOC2, ISO 27001, PCI DSS, GDPR, or HIPAA certifications until formal third-party audits are completed.
5. Platform Security Controls
Technical Safeguards Protecting Platform & Workspace Integrity
JWT Authentication
Signed stateless tokens for verified user login sessions.
Role Based Access (RBAC)
Scoped permissions for Merchant Owners, Staff, and Admins.
Store Workspace Isolation
Schema boundary segregation preventing cross-tenant access.
Website Version Snapshots
Immutable layout state snapshots created on every publish.
Deployment Audit Logs
Historical records of publish timestamps, authors, and CDN purges.
System Audit Logs
Tracking critical store settings, role changes, and key edits.
1-Click Version Rollback
Instant restoration to any previous working website snapshot.
Private Draft Preview
Signed preview URLs protect draft edits from public view.
Background Autosave
30-second background autosaving keeps canvas edits safe.
6. Website Security & Publishing Pipeline
Stage-by-Stage Publishing Architecture & Version Safeguards
The TWAICY Website Builder is engineered with a strict 4-stage deployment pipeline to ensure unsaved edits never break your active online storefront.
Draft Canvas State
Make changes to theme tokens, sections, and navigation. Canvas edits stay in draft mode and are never visible on your live storefront.
Private Signed Preview
Generate short-lived signed JWT preview links. Share with team members to preview exact mobile/desktop renders prior to publishing.
Publish Validation Check
Automated engine validates missing links, draft blocks, and SEO metadata. Creates an immutable version snapshot backup.
Live Storefront Sync
One-click deployment pushes changes to the live storefront and purges CDN edge cache instantly. 1-click rollback available anytime.
7. Shipping Integrations
Merchant Courier Credentials & Direct Account Connections
Merchants link their own official courier accounts. TWAICY never owns, holds, or manages merchant courier credentials or freight wallet balances.
Shiprocket Integration
Connect your own Shiprocket API secret keys for automated AWB generation, label printing, and tracking.
Delhivery Direct
Direct B2C courier API dispatch through your official merchant account.
Self Delivery / Local Fleet
Manage your own local store drivers, custom radius fees, and doorstep cash collection.
8. Platform Architecture Flow
End-to-End Commerce Operational Flow
The TWAICY Commerce OS connects merchant workspace controls, website publishing, real-time inventory ledgers, direct payment channels, and courier APIs into an integrated workflow.
Merchant
Authenticated Workspace Owner
Website Builder
JSON Canvas Engine & Themes
Orders
Real-Time Ledger & Inventory
Payments
Direct Settlement Gateway
Shipping
Merchant Courier Dispatch
Customers
Fulfillment & Retention
9. Frequently Asked Questions
Common Merchant Trust & Security Inquiries
10. Contact Security & Support
Security Vulnerabilities & Platform Technical Assistance
We take platform security, merchant data privacy, and responsible vulnerability disclosures seriously. Reach out directly to our engineering desks.
For vulnerability reports & security research disclosure.
