Security
Permission before action.
This describes how ToolHub is being built. The live service is not open yet.
Credentials stay with their merchant
In the service being developed, each merchant's credentials will be encrypted at rest, never logged, and used only for that merchant's requests. ToolHub will ask for the least-privilege scopes it needs.
Provider APIs and controlled access
ToolHub will use provider APIs and official OAuth where supported, or API keys controlled by the merchant. There will be no scraping or unofficial WhatsApp connection.
Confirm actions that change things
Actions that ship a parcel, issue a refund or message a customer will require confirmation. Merchants will be able to see an audit log of every action.
Disconnect and delete
Merchants will be able to disconnect any tool and request deletion of their data at any time.
This website and the sample-data demo
Waitlist and contact submissions are validated on the server, checked by Turnstile and rate limited. IP addresses are hashed with a secret salt before storage. Form contents and credentials are not written to application logs.
The demo is designed to use only bundled fake data and simulated actions, with no calls to real stores, couriers, payment providers or WhatsApp.
Report a vulnerability
Email a vulnerability report. Please avoid including merchant credentials or customer data.