Skip to main content

Trust and Security Requests

Last reviewed: August 5, 2026

eshopOS publishes its core legal terms, privacy commitments, provider register, and public control summaries. Some security and due-diligence material requires a controlled review because unrestricted publication could weaken platform or merchant security.

Publicly available material

The following documents are available without an application:

Materials that may require review

Depending on the requester's relationship with eshopOS and the purpose of the review, additional material may include:

  • Security questionnaire responses.
  • High-level architecture or data-flow summaries.
  • Business continuity and recovery summaries.
  • Subprocessor or international-transfer supporting information.
  • Penetration-test or assessment summaries when available and suitable for disclosure.
  • Contractual security or data-processing addenda for an eligible engagement.

Availability is not guaranteed. Documents may be limited, redacted, covered by confidentiality terms, or unavailable where disclosure would create security, contractual, legal, or third-party risk.

Submit a request

Request a trust and security review from a business email and include:

  1. Your name, role, and organization.
  2. Your relationship to eshopOS or the merchant you represent.
  3. The specific documents or questions needed.
  4. The business, procurement, compliance, or security purpose.
  5. The relevant deadline and jurisdiction.
  6. Whether your organization can sign a confidentiality agreement.

Requests that do not identify a legitimate business purpose may be declined.

Review and access process

  1. eshopOS verifies the requester and the relationship to the account or prospective engagement.
  2. The request is reviewed for legal, contractual, privacy, and security risk.
  3. eshopOS determines which documents can be shared and whether redaction or a confidentiality agreement is required.
  4. Approved material is shared through a controlled, time-limited channel where supported.
  5. Access may be revoked when the review ends, the link expires, or the stated purpose changes.

Submitting a request does not create an audit right, certification, service commitment, or obligation to disclose restricted material unless a binding agreement says otherwise.

Information that is not disclosed

eshopOS does not provide credentials, secrets, exploit details, private keys, raw security logs, internal IP addresses, unrestricted production access, unredacted vulnerability reports, customer data, or information belonging to another merchant.

Urgent security reports

Do not use the trust-review process to disclose an active vulnerability or incident. Send urgent security information to support@ossarian.com with the subject Security report and avoid including credentials or customer data in the first message.