Trust & Safety
Security & Data Protection
How Cossa Store protects customer accounts, orders and personal information through practical security controls.
Last updated
5 September 2026
Security review framework
Our security review covers identity and authentication; authorisation and admin access; session and token handling; privacy and personal information; API and server boundaries; database permissions and row-level security; payment and webhook integrity; checkout, orders and fulfilment; delivery and supplier integrations; catalogue and content integrity; infrastructure, deployment and secrets; monitoring, incident response and recovery; and independent testing and assurance.
This public summary describes the areas under review without publishing internal routes, identifiers, credentials or operational security details.
Current control status
Email-confirmed access, server-side Store administrator authorization, protected admin sessions, payment-provider hosted card entry and server-side payment verification are active controls.
Administrator authenticator enrollment is ready for the approved owner and remains private. Customer single-session enforcement, independent external penetration testing and a formal recurring review cadence are still being completed or planned; they are not represented as finished controls here.
Our commitment
Cossa Store is operated by Cossa Nexus Holdings (Pty) Ltd. We use reasonable technical and organisational safeguards to protect customer accounts, orders, delivery information and other personal information.
Security is an ongoing responsibility. We review access, data handling and operational controls as the Store and its service providers change.
Accounts and access
Customer accounts are protected by password-based authentication and secure session controls. Internal administration is restricted to specifically approved Store administrators and is separated from ordinary customer access.
Use a unique password, keep it private, sign out of shared devices and contact us promptly if you suspect unauthorised access.
Payments
Approved payment providers host or process card and banking transactions. Cossa Store does not ask for or intend to store complete card numbers, CVV codes, card PINs or online-banking passwords.
We receive only the transaction details reasonably needed to confirm, reconcile, support or refund an order.
Personal information
We limit access to personal information to people and service providers who need it to operate the Store, support customers, process payments, arrange delivery, fulfil orders or meet legal obligations.
Our Privacy Policy explains what information we collect, why we use it and the choices available to you.
Monitoring and response
We use authentication, access controls, secure connections, logging and monitoring appropriate to the Store's risks. Where we identify a security concern, we investigate it, contain it where possible and take reasonable follow-up action.
No internet service can promise absolute security. Please report suspected account misuse, misleading Store content or a security weakness as soon as possible.
Report a security concern
Email cossa@cossanexusholdings.co.za with the affected page or account, what you observed and when it occurred. Do not include passwords, full card numbers, CVV codes, banking passwords or other secrets. We may contact you to verify the report and request safe supporting details.
Related information
For personal-information rights, retention and sharing details, read the Privacy Policy. Store terms, delivery and returns information are available from the footer and checkout.
Read our Privacy Policy for detailed information about personal data.
