Trust and Security Requests
Last reviewed: August 5, 2026
eshopOS publishes its core legal terms, privacy commitments, provider register, and public control summaries. Some security and due-diligence material requires a controlled review because unrestricted publication could weaken platform or merchant security.
Publicly available material
The following documents are available without an application:
- Terms of Service
- Privacy Policy
- Data Processing Agreement
- Service Providers, Subprocessors, and Connected Platforms
- Compliance Controls
- System Status
Materials that may require review
Depending on the requester's relationship with eshopOS and the purpose of the review, additional material may include:
- Security questionnaire responses.
- High-level architecture or data-flow summaries.
- Business continuity and recovery summaries.
- Subprocessor or international-transfer supporting information.
- Penetration-test or assessment summaries when available and suitable for disclosure.
- Contractual security or data-processing addenda for an eligible engagement.
Availability is not guaranteed. Documents may be limited, redacted, covered by confidentiality terms, or unavailable where disclosure would create security, contractual, legal, or third-party risk.
Submit a request
Request a trust and security review from a business email and include:
- Your name, role, and organization.
- Your relationship to eshopOS or the merchant you represent.
- The specific documents or questions needed.
- The business, procurement, compliance, or security purpose.
- The relevant deadline and jurisdiction.
- Whether your organization can sign a confidentiality agreement.
Requests that do not identify a legitimate business purpose may be declined.
Review and access process
- eshopOS verifies the requester and the relationship to the account or prospective engagement.
- The request is reviewed for legal, contractual, privacy, and security risk.
- eshopOS determines which documents can be shared and whether redaction or a confidentiality agreement is required.
- Approved material is shared through a controlled, time-limited channel where supported.
- Access may be revoked when the review ends, the link expires, or the stated purpose changes.
Submitting a request does not create an audit right, certification, service commitment, or obligation to disclose restricted material unless a binding agreement says otherwise.
Information that is not disclosed
eshopOS does not provide credentials, secrets, exploit details, private keys, raw security logs, internal IP addresses, unrestricted production access, unredacted vulnerability reports, customer data, or information belonging to another merchant.
Urgent security reports
Do not use the trust-review process to disclose an active vulnerability or
incident. Send urgent security information to support@ossarian.com with the
subject Security report and avoid including credentials or customer data in
the first message.