Customers trust Merch OS with their brand assets, their people’s addresses, and their spending. This page describes the controls we operate to protect that data. It reflects what is in place today, not what is planned.
Last updated: August 2026
Merch OS is a hosted service running entirely on managed cloud platforms. Brandmerch operates no physical servers, data centers, or office networks. Our application runs on Render, our frontend on Vercel, and we use Amazon Web Services for object storage, content delivery, and audit logging. Each of these providers maintains its own independent security attestations, which we review at least annually as part of vendor management.
Card payments are processed entirely by Stripe, a PCI DSS Level 1 service provider. Card numbers are never transmitted to or stored on Brandmerch systems. Payment webhooks are cryptographically signature-verified before they are processed.
Every production change is made through a pull request into a protected branch. No one — including administrators — can push directly to production code.
In August 2026 we commissioned an external, unauthenticated black-box security assessment of brandmerch.com by an independent offensive security firm. The assessment crawled 285 URLs across 76 test classes and 179 detected injection points. It returned no critical, no high, and no medium severity findings, and one low-severity configuration finding. We repeat independent testing periodically and expand scope over time.
Our production database is backed up continuously by our hosting provider with point-in-time recovery. Restore procedures are documented in an internal runbook, and our recovery capability has been exercised against real production data rather than assumed.
We maintain a documented incident response plan covering identification, containment, resolution, and post-incident root cause analysis. Where an incident affects customer data, we notify affected customers in line with our contractual commitments and applicable law.
Brandmerch is actively working toward SOC 2 Type II. We use continuous compliance monitoring to track our controls, and our subprocessors maintain their own independent security attestations. We are happy to discuss our current status and share available documentation with prospective customers under NDA.
We welcome reports from security researchers and treat them seriously. Our full vulnerability disclosure policy — including scope, ground rules, and our commitment not to pursue good-faith researchers — is published in the Legal Center, and our machine-readable contact file is at /.well-known/security.txt.
Security questions from customers or prospects, and vulnerability reports, both go to security@brandmerch.com.