Security

Nine layers between your business and a bad day

Protection is built into the platform, not bolted on. Every order, login and payment passes the perimeter first, so fraud, abuse and bad actors are stopped before they ever reach your data.

Defense in Depth

Every request runs the gauntlet

Orders, logins and payments travel the same guarded path. Each ring inspects, verifies and clears legitimate traffic, while threats are turned back at the layer they hit, long before they reach the core.

The Nine Layers

Protection at every entry point

Each layer does one job well. Together they cover signup, sign-in, checkout and every action in between.

BotShield & Spam Protection

Automated signups and form abuse are filtered out before they ever reach your data.

Brute-Force Protection

Repeated login attempts are throttled and locked out automatically, per action and per window.

Fraud Detection

The built-in WFraud engine screens each order by email, phone and IP, and MaxMind and FraudLabs Pro can be added optionally.

Two-Factor Authentication

Two-factor sign-in for staff and clients via authenticator app (TOTP), SMS or email, and can be required by policy where you want it.

Sensitive Data Encryption

Credentials and personal data are encrypted at rest in the database, not stored in the clear.

Proxy & VPN Blocking

Anonymized traffic can be challenged or blocked at signup and checkout, or allowed per client.

Location, IP & Browser Verification

Unusual sessions trigger re-verification before account access, by city, IP block or ASN.

Client Blacklist

Block known-bad emails, phones and IPs before checkout, and share those blocks across WISECP installations.

Document Verification

Rule-based filters automatically decide which client must submit which document, then route it to approval.

Under the Hood

Hardened where it counts

The plumbing is as guarded as the front door. Sessions, forms and requests each pass through their own defenses.

Session Security

Geo-located login history, session logs, and remember-me tokens revoked the moment a password changes.

CSRF Protection

System-wide CSRF tokens (HMAC-SHA256), AJAX-aware, on every state-changing request.

Form Security Layer

CSRF, BotShield, process restriction and captcha guard every public form together, not one at a time.

Captcha, Everywhere

Four providers, including reCAPTCHA v3, hCaptcha and Turnstile, across nine protected surfaces.

Visibility & Control

Know who did what, and who can

Every action leaves a record and every role has a boundary, so you always have both the history and the guardrails.

See the Platform
  • Every action is logged and filterable by client, system and staff, each entry stamped with its IP.
  • Token-redacted API logs, plus DB query, session, SMS and email logs.
  • Privilege Groups give every staff role granular, scoped access.
  • Two-factor sign-in enforceable for staff, not just clients.

Recovery

Backups you don't have to think about

Scheduled, retained and shipped off-site automatically, so a bad day never turns into a lost one.

  • Hourly, daily, weekly and monthly schedules with retention rules.
  • Six off-site destinations: FTP, SFTP, Google Drive, OneDrive, Bunny Storage and Yandex Disk.
  • Keep-local copies, path and table exclusions, and a live disk-usage view.
  • Upload progress, diagnostics and a one-click self-test.

See It in Action

Security that works while you sleep

Take a live demo and watch the perimeter do its job, or explore the platform behind it.