# [Rebilder security](https://rebilder.com/security)

> How Rebilder protects credentials, payments and business data.

- **Description:** How Rebilder protects accounts, payments and business data, with guidance for reporting a security issue.
- **Organization:** Rebilder

## Your credentials

- Site API keys are stored as one-way hashes. Save your key when it is created, and replace it from the Console when needed.
- Shopify connection tokens are encrypted at rest.
- Incoming webhook and internal API requests are authenticated before processing.

## Payments

- Our payment provider handles card entry and billing. Rebilder stores your subscription status and billing references without storing card details.

## Data isolation

- Access controls restrict merchant records to authorized accounts and service operations.
- Rebilder and Mumm maintain separate account data. Shared website benchmarks require at least 25 independent sites. Our Privacy Policy describes the commitments that apply.
- Queries are screened for personal information before they are stored.

## Your site’s independence

- The self-hosted gateway runs in your infrastructure and falls back to your normal response when a source or renderer fails.
- The CLI and scanner MCP server process scans locally without uploading scan data to Rebilder.

## Responsible disclosure

Report vulnerabilities to security@rebilder.com. We acknowledge reports within two business days, do not pursue good-faith research and credit reporters who want credit.

## Related

- [Privacy policy](https://rebilder.com/legal/privacy)
- [Status](https://rebilder.com/status)