1. Our approach
Security is part of delivery, not an add-on. Every engagement — from a single-brand storefront to dedicated AI development — is built on the same managed platform, so the controls below apply to every customer, on every tier, from day one.
- Fully managed infrastructure: we operate it, patch it and monitor it on your behalf.
- Least privilege: people and systems get the access they need for their job, no more.
- Defence in depth: network, application and data layers are each protected independently.
- Transparency: what we commit to is written into the contract, not only on this page.
2. Data ownership and access
Your data stays yours. You retain ownership of all intellectual property in your Customer Data — your catalogue, your orders, your customers (Terms and Conditions, clause 6.2).
We do not look unless we need to. 3D360 Systems does not access or use Customer Data except as necessary to maintain or provide the Services, or to comply with the law or a binding order of a governmental body (clause 8.4). Access to Customer Data outside of those cases requires your prior written consent (clause 6.2).
You choose where it lives. You may specify the region in which Customer Data is stored and it will be kept and processed in the regions you select (clause 8.4).
Personal data is handled separately. Where the Services need to process personal data on your behalf, we enter into a suitable data sharing agreement first (clause 8.2). Our own processing of personal data is described in the Privacy Policy.
3. Infrastructure
- Encryption in transit. All traffic to the Site and to customer storefronts is served over HTTPS (TLS). Plain HTTP is redirected.
- Encryption at rest. Databases, object storage and backups are encrypted at rest by the underlying cloud provider.
- Isolation. Each customer’s storefront and data are logically separated; multi-brand customers run every brand inside their own tenant.
- Monitoring. Border routers and core switches are checked by our monitoring tools at least every 15 seconds (Terms and Conditions, Schedule 1). Application-level alerts page the on-call engineer.
- Availability. Unless an Order says otherwise, we commit to 99% network availability in any calendar month, with service credits where an Order provides for them (Schedule 1).
- Patching and maintenance. Scheduled maintenance is announced in advance; unscheduled maintenance is reserved for incidents that would otherwise cause prolonged downtime (Schedule 1).
- Backups. Customer databases are backed up on a regular schedule and restore procedures are tested.
4. Payments
Card payments are handled by a third-party payment processor; statements may show “3D360 Systems” or “Stripe” (Terms and Conditions, clause 5.5). We never store full card numbers on our own systems — card data is captured and tokenised by the processor, which maintains its own PCI DSS certification.
5. Access control
- Access to personal information is restricted to the people who need it for the relevant purpose (Privacy Policy, section 5).
- Production access requires individual accounts with multi-factor authentication.
- Administrative actions on customer environments are logged.
- Access is reviewed when roles change and revoked promptly when someone leaves.
- Our suppliers are prohibited from using personal data for any purpose other than delivering their services to us (Privacy Policy, section 3).
6. AI and your data
Recommendation engines, forecasting models and AI customer-service agents are trained and run on your own product, order and interaction data, and that processing happens solely to deliver your Services (Terms and Conditions, clause 8.4). Dedicated AI Development engagements — knowledge management, R&D tooling, operations models — are scoped in a written Order that states what data is used and where it is processed.
We do not engage in fully automated decision-making that has a legal or otherwise significant effect on individuals (Privacy Policy, section 8).
7. Fraud prevention
To protect storefronts and shoppers we use limited automated controls that do not have a legal or otherwise significant effect on you: a temporary deny list of IP addresses associated with repeated failed transactions (held for a small number of hours) and a temporary deny list of cards associated with those addresses (held for a small number of days) (Privacy Policy, section 8).
8. Incidents and disclosure
If we become aware of a security incident affecting your data we will notify you without undue delay, tell you what we know, what we are doing and what you should do, and keep you updated until it is resolved. Customers must likewise inform us as soon as reasonably possible of any unauthorised access they become aware of (Terms and Conditions, clause 4.1(e)).
Found a vulnerability? Report it to info@3d360systems.com with “Security report” in the subject. Please give us reasonable time to investigate and fix the issue before disclosing it publicly, and do not access, modify or exfiltrate data that is not yours while testing. We will acknowledge reports and keep you informed of progress. We do not currently run a paid bug bounty programme.
9. Compliance and questionnaires
We do not currently hold third-party certifications such as SOC 2 or ISO 27001. We are transparent about that, and we will say so on this page when it changes. Each party remains responsible for its own compliance with applicable export-control, sanctions, AML and KYC requirements (Terms and Conditions, clause 14).
If your procurement process needs a security questionnaire, a data processing agreement or a description of specific controls, contact info@3d360systems.com and we will work through it with you.