Security
User security
Optimizely Configured Commerce has two groups of users console users and website (storefront) users. Console users can only access the Admin Console and have roles starting with ISC .
Optimizely's cyber-security and compliance
Optimizely is committed to protecting and securing customer data and also implementing the necessary controls to assist its customers in achieving regulatory compliance. To achieve this goal, Optimizely continually conducts assessments to ensure compliance to the General Data Protection Regulation (GDPR) and also to the Payment Card Industry Data Security Standard (PCI-DSS).
Security assessments
Optimizely is committed to providing secure products and services. Part of this commitment is performing security assessments, such as vulnerability assessments, risk assessments, and third-party penetration tests, to determine the presence of threats and vulnerabilities within the products and services.
Privacy policy
Creating effective privacy controls is essential for compliance with various state and national privacy laws. It is also required for meeting customer privacy expectations.
Set security headers
If you want to increase the security of your Optimizely Configured Commerce site, you can use the Content-Security-Policy header. You can find this setting under Administration > Settings > Site Configurations > Security Headers in the Admin Console.
Show IdentityServer discovery endpoints
You can expose or hide discovery endpoints for Identity Server. This global setting is only available to ISC System and ISC Implementer users.
Enable reCAPTCHA
To ensure email processing is secure and prevent robots from sending bad emails from your site, Optimizely Configured Commerce requires that users be authenticated when using features that generate emails, including Contact Us form Share Product on the Product Detail page Create Account form Forgot Password on the Sign In page Share Order on the Order Status page When users trigger emails using these features, the site checks if they are logged in. If the users are logged in, they can generate emails as usual during their session.
Turn on cookie/privacy policy pop-up
Turn on the Cookie/Privacy Policy pop-up in Optimizely Configured Commerce for new site customers to review and accept your cookie and/or privacy policy. Insert content that meets applicable compliance and privacy laws.
View audit log
In the Admin Console, the audit log displays events such as logins, changes to application settings, access to certain parts of the Admin Console, password changes, the initialization of the Optimizely Configured Commerce application, and more. The audit log records the following activities Composable service visits – Navigating to any composable service page (Payment Service, Search Service, PIM Service, etc.
View the dates for admin console records
For audit purposes, there is a five-point data set that is kept for each record saved to Configured Commerce Created On, Created By, Modified On, Modified By and ID. Access this information in the Admin Console by going to the record in question and clicking the Information icon.
Schrems II, Personal Identifiable Information (PII), and geofencing in Configured Commerce
The European Union Schrems II consumer data protection legislation requires “adequate levels of data protection" for all E. U.
Manage Personal Identifiable Information (PII) data
Administrators can access attributes within the Application Dictionary, user profiles and System Lists that can work together to ensure that unauthorized users cannot access Personal Identifiable Information (PII) data. These features can provide additional data security for consumers, which some regions require by law .
Disaster recovery
Optimizely's resources are virtualized, redundant, and spread across multiple Availability Zones (data centers) at all times. Full backups of production databases are taken every 24 hours for the resolution of Disaster Recovery incidents, with transaction log backups providing point-in-time recovery.
Whitepaper: Configured Commerce integration HTTP versus VPN
Optimizely has implemented a variety of integration capabilities within Optimizely Configured Commerce that allows it customers to transfer data between their internal systems and Configured Commerce. The implementation of this data transfer involves the use of services that send data over a Hypertext Transfer Protocol (HTTP) session encrypted with Transport Layer Security (TLS), aka HTTPS.