Security Management & Technical Safeguards
We at WordMagic CMS implement a multi-layered security system to ensure the integrity and confidentiality of your information. This document describes the technical standards we follow.
§I Technical Security Measures
- Encryption (SSL/TLS): All data transmitted between your browser and our servers is protected by TLS (HTTPS) encryption.
- Password Hashing: We never store passwords in plain text. Modern hashing algorithms (bcrypt/argon2) are used.
- Data Isolation: SaaS version customer data is logically isolated at the database level to prevent unauthorized access.
- Protection against automated attacks: We use the Google reCAPTCHA system to identify bots and prevent spam attacks. This ensures resource stability and protects input forms from malicious use.
§II Financial Transaction Security
Payment security is ensured according to the PCI DSS standard through our partners (Stripe, PayPal, Braintree, Fondy):
- We do not collect, process, or store bank card data on our own servers.
- All payment forms operate through secure iFrames or redirects directly on the payment gateway side.
§III Infrastructure and Backups
- Data Centers: Our servers are located in secure EU data centers that comply with ISO 27001 standards.
- Backups: We perform daily backups of critical data. Backups are stored in encrypted form in a separate storage.
- Monitoring and anti-flood: We conduct 24/7 monitoring for unauthorized access attempts, which, combined with Google's cloud traffic filtering algorithms, provides effective counteraction against DDoS attacks and malicious scripts.
§IV Personnel Access
Access to customer data is restricted to authorized WordMagic CMS developers solely for technical support or fixing critical bugs. We use two-factor authentication (2FA) for access to infrastructure management panels.
§V Incident Response
In the event of a data breach, we commit to notifying users and relevant supervisory authorities within 72 hours of establishing the breach, in accordance with GDPR requirements.
Last updated: 02-03-2026