Trust & Security

Trust Center

EasyEcom runs order, inventory and warehouse operations for 1,800+ brands and 3PLs across 12+ countries. This page explains how we secure that platform: the certifications we hold, the controls behind them, and the documentation your security and procurement teams can request.

Last reviewed · Aug 2026 Applies to · easyecom.io & the EasyEcom platform
SOC 2 Type IIIndependent attestation, renewed annually
ISO 27001Certified information security management system
GDPRAligned processing, DPAs and standard contractual clauses
VAPTRegular independent vulnerability assessment & penetration testing

01Overview

Security is a precondition for everything EasyEcom does. The platform sits in the middle of our customers' commerce operations — orders, inventory, shipments, settlements and the end-customer data that flows with them — so we treat the confidentiality, integrity and availability of that data as a core product requirement, not a compliance checkbox.

Our security program combines independent certification and attestation (ISO 27001, SOC 2 Type II), recurring independent testing (VAPT), GDPR-aligned data protection practices, and layered technical and organizational controls across the platform. This page summarizes each of these; the Privacy Policy covers how personal data is handled in detail.

02Certifications & attestations

SOC 2 Type II

EasyEcom holds a SOC 2 Type II attestation. An independent auditor examines the design and operating effectiveness of our controls over a sustained observation period — not just at a point in time — covering security, availability and confidentiality. The attestation is renewed annually; it was most recently renewed in 2026 (see the announcement in our newsroom).

The full SOC 2 Type II report is available to customers and prospects under NDA: see Reports & documentation.

ISO 27001

EasyEcom is ISO 27001 certified. Our information security management system (ISMS) governs how we identify risk, control access, handle data, manage vendors and respond to incidents, and it is subject to recurring surveillance audits by the certifying body. The certificate is available to your procurement team on request.

03Compliance & data protection

GDPR & UK GDPR

Our processing of personal data is GDPR-aligned. Depending on the service, EasyEcom acts as a data processor (for order, inventory and end-customer data processed on behalf of business customers) or as a data controller (for our own accounts, billing and communications). Cross-border transfers rely on recognized mechanisms such as the European Commission's Standard Contractual Clauses. The lawful bases we rely on and the rights available to you are set out in the Privacy Policy.

India DPDP Act, 2023

For personal data of individuals in India, we process data in accordance with the Digital Personal Data Protection Act, 2023, including rights of access, correction, erasure and grievance redressal: detailed in the regional disclosures of our Privacy Policy.

Data processing agreements

A data processing agreement (DPA) governs our processing of business customer data where required by applicable law, and is part of every enterprise contract. It sets out each party's responsibilities, our confidentiality and security obligations, and the terms under which subprocessors are engaged.

Independent testing (VAPT)

The platform undergoes regular independent vulnerability assessment and penetration testing (VAPT). Findings are triaged by severity and remediated through our engineering process, and a summary of the most recent assessment can be shared with your security team under NDA.

04Platform & infrastructure security

EasyEcom applies layered technical safeguards across the platform:

  • Encryption. Data is encrypted in transit and at rest using industry-standard protocols.
  • Access control: role-based access on the platform, with authentication and session controls; internal access follows least privilege and is limited to personnel who need it for legitimate business functions.
  • Monitoring & logging: ongoing monitoring of platform and system activity to detect unauthorized or anomalous behaviour.
  • Resilience & backups: secure infrastructure practices with routine backups; residual copies cycle out of backups on a defined schedule.
  • Scale headroom: the platform is load-tested for 10 million orders a day, so peak events don't degrade the controls above.

Credentials and integration tokens that customers authorize (marketplaces, carriers, storefronts, ERPs) are stored and handled with the same safeguards, and we do not store complete card or financial credentials.

05Data residency & reliability

EasyEcom is live in 12 countries across APAC, the Middle East, Europe and North America. Data residency is configurable across India, US, EU, UK and APAC regions, so customers can keep data in the region their compliance posture requires.

Enterprise plans carry SLA-backed uptime commitments (99.97%), and platform availability is published on our system status page.

06Organizational security

Technology controls only work when the organization around them holds. Our ISMS extends to how the company itself operates:

  • Access to customer data is restricted to authorized personnel under confidentiality obligations, on a least-privilege basis.
  • Vendors and subprocessors are evaluated before onboarding and engaged under contractual security and confidentiality terms: see Subprocessors.
  • Security practices are reviewed and strengthened on a recurring basis to adapt to evolving threats, and incident response procedures cover detection, escalation and customer notification where required.

07Reports & documentation

Security and procurement teams evaluating EasyEcom can request the following, under NDA where required:

DocumentWhat it covers
SOC 2 Type II reportIndependent attestation of control design and operating effectiveness
ISO 27001 certificateCurrent certification of our information security management system
VAPT summaryScope and outcome of the most recent independent penetration test
Data processing agreementProcessing terms, security obligations and subprocessor provisions
Subprocessor listNamed list of current subprocessors, by category and region

During enterprise procurement we will also walk your security team through hosting, data handling and retention directly.

08Subprocessors

EasyEcom engages a limited set of third-party subprocessors: cloud hosting, communications delivery, analytics and monitoring, payment processing, support tooling, and security and backup services: each under contractual terms that require them to protect data consistently with our Privacy Policy and applicable law. EasyEcom remains responsible for the data we entrust to them.

The categories we use, how subprocessors are vetted, and how customers are notified of material changes are documented on the Subprocessors page.

09Contact & reporting

If you have a security question, need documentation for a vendor assessment, or believe you have found a vulnerability in EasyEcom, contact us: reports of suspected vulnerabilities are reviewed and acted on with priority.

Security & privacy contact

Entity: EasyEcom

Email: privacy@easyecom.io

Documentation requests: via your account manager, or the email above

EasyEcom · 2nd Floor, Building 209, Hustle Hub, 27th Main Road, HSR Layout, Bengaluru 560102, India · privacy@easyecom.io