Security

⚠ Draft for review — professional legal review required before launch

Licensing responses are cryptographically signed; the plugin verifies them offline. Update packages are hash-verified and delivered through short-lived, single-use tokens — never public URLs.

Your store never depends on our availability: validation results are cached with a grace window, and the licensing layer has no code path into storefront operation.

Report a vulnerability: security@wooaccount.com. We acknowledge reports within one business day.