Writing
We checked 16 ecommerce operations vendors. Three publish a security certification.
Sixteen vendor websites, read in one pass on 28 August 2026. Three name a security certification. Six have no security page at all. None publishes a sub-processor list. Here is what to ask instead of trusting the adjectives.
We read the public websites of sixteen ecommerce operations vendors on 28 August 2026 and looked for one thing: what a buyer can verify without signing an NDA or booking a call.
The vendors: Linnworks, Brightpearl, Cin7, Extensiv, Veeqo, ChannelEngine, Rithum, Lengow, PlentyONE, Billbee, Xentral, Channable, Productsup, Akeneo, Plytix and Sales Layer.
Everything below is a fact about a website on a date, not a judgement about a company. Certifications are held privately far more often than they are published, and a vendor with no security page may have an excellent security programme. That is rather the point: you cannot tell.
Three of sixteen name a certification
| Vendor | What the site names |
|---|---|
| ChannelEngine | ISO 27001, since 2022 |
| Rithum | SOC 2 Type II |
| Productsup | ISO 27001 |
The other thirteen do not name one on their site. Six have no security page at all — no trust centre, no compliance page, nothing between the pricing page and the privacy policy.
Nobody in the EU-facing group publishes a sub-processor list
Not one of the sixteen publishes the list of sub-processors it uses.
This is the omission that should bother a European buyer most, and it is the cheapest one to fix. If you are a controller under the GDPR, your processor’s sub-processors are your problem: Art. 28(2) requires the processor to have your authorisation to engage them, and Art. 28(4) makes the processor liable for them. A DPA that promises to notify you of changes to a list you have never seen is a promise about a document that does not exist publicly.
The Commission’s own standard contractual clauses for controllers and processors assume you can identify who is processing the data. A published list is how a vendor makes that answerable before the contract rather than after it.
Nine of sixteen publish no pricing, and every published price is qualified
Nine of the sixteen sites show no price at all. Every price that is published carries a qualifier — “starting at”, or a cap tied to GMV, or a band that resolves on a call.
There is a defensible reason for this in a business where implementation cost dominates licence cost. There is also a less defensible one, and a buyer cannot distinguish them from outside. What a buyer can do is ask which of the two it is, and ask for the meter: what is counted, when it is counted, and what happens when the count grows.
Eight of sixteen have a 404 on a URL their own navigation links to
This is the finding we expected least and rechecked most.
Broken on 28 August 2026: Akeneo’s /pricing and /trust-center, Channable’s
/security, Extensiv’s /pricing, Rithum’s /pricing, Productsup’s
/security, ChannelEngine’s trust-centre link, and several Xentral feature
URLs.
A dead link is not a security finding. But /trust-center and /security
returning 404 from a live nav is a fact about how closely anyone is reading
those pages — and the trust page is the one page whose whole job is to be
current.
What to ask instead
Adjectives are free. “Enterprise-grade”, “bank-level” and “military-grade” are not claims anybody can fail. These five questions have answers that can be wrong, which is what makes them worth asking:
- Which certification, issued by whom, covering which scope, valid until when? “ISO 27001” without a scope statement can cover a single office.
- Where is the sub-processor list, and how am I notified before it changes? Before, not after — Art. 28(2) is about authorisation.
- Where is the data, and who can reach it? Region, and which staff roles have production access.
- What is your last penetration test, and will you share the summary? A summary letter is normal to share; the full report is normally not.
- What happens on exit? Export format, retention period, deletion evidence.
If a vendor cannot answer 1 and 2 from a public page, you have learned something about how long the answers take internally.
Where TOVIA stands
We hold no security certification. Not ISO 27001, not SOC 2 — neither is in progress, and a pre-launch product with no production deployment could not meaningfully hold either yet.
What exists instead is a published inventory of twelve controls with the state of each one, including the ones that are not in place. That is on Security & trust, which also carries the certification status as the first thing on the page rather than the last.
We wrote this article knowing it invites the same audit of us. That seemed like the right way round.