ReadyCMS 3.0.63 is live. · Read the changelog
Platform · Security & compliance

Security that's built in, not bolted on

Every ReadyCMS store runs behind a purpose-built web application firewall, a hardened application layer, and GDPR data tooling - built, maintained and monitored by the same team that builds the platform. Nothing is bolted on afterwards: no security plugins to install, configure or keep current.

01 · Web application firewall

A firewall in front of every store

ReadyCMS ships its own application-layer WAF that runs before PHP or your database is touched - filtering malicious traffic at the edge of the application, on every tenant, by default.

Bot & scanner filtering

350+ malicious user-agent signatures and 151 exploit and scanner rules block PHP exploits, shells and automated probes before they reach the app.

IP blocklists at scale

IP and CIDR blocklists matched with a Bloom filter - fast set membership that stays cheap even under heavy, hostile traffic.

Rate limiting & auto-ban

Abusive clients are rate-limited and then automatically banned, so a brute-force or credential-stuffing run gets cut off entirely instead of just slowed down.

Honeypots & request inspection

Fake admin and login paths trap bad actors, while suspicious queries, headers and oversized payloads are inspected on every request.

ASN & GeoIP enrichment

Every request is enriched with ASN and GeoIP context and scored on it, so blocking decisions weigh where traffic actually originates, alongside its headers.

Live monitoring

A real-time attack radar and event stream show what's being blocked as it happens - security you can watch, not just trust.

Traffic scored and filtered worldwide, in real time.

02 · Application hardening

Hardened at the code level, too

The firewall stops traffic at the door. Inside, every request is written against the same defensive standards - so the application isn't relying on the perimeter alone.

CSRF protection

State-changing requests are guarded by synchronizer CSRF tokens, so actions can't be forged from another site.

SQL-injection defense

Database access uses PDO prepared statements with identifier whitelisting - user input never becomes SQL.

XSS & output sanitizing

Incoming requests are sanitized and HTML output passes through a dedicated sanitizer - cross-site scripting is contained on both ends.

Upload hardening

Uploads run against an executable-extension deny-list and path-traversal guards, so the media library can't become an attack vector.

Brute-force & 2FA

Login-anomaly detection and reset-rate limiting slow attackers, and TOTP two-factor authentication protects admin accounts.

Fraud risk signals

Order and account activity are scored for fraud risk, surfacing the signals that matter before a bad order ships.

03 · Data protection & GDPR

GDPR requests, handled by tooling

Data-subject requests shouldn't mean a manual database hunt. ReadyCMS ships tenant-scoped tooling for the two rights that come up most - access and erasure.

Right of access

Export everything held about a visitor - their event history and personalization profiles - to a single file to hand to the requester.

Right to erasure

Delete a visitor's data across the event stream and caches - with a dry-run preview first, so you confirm exactly what's removed.

Tenant isolation

Every store runs on its own database, so one tenant's data is separated from another's by design - not by a shared-table filter.

Visitor tracking data is handled by the GDPR export/erasure tooling above; account-level records (orders, profiles) are managed from the admin. Ask us about your data-processing requirements, or read the Trust & Security overview for data protection, GDPR and sub-processor details.

04 · One accountable stack

Security you don't have to assemble

On plugin-stack platforms, security is a shopping list - a firewall plugin here, a 2FA plugin there, each with its own update cycle and its own vendor to chase. On ReadyCMS it's part of the platform, maintained and monitored by one team.

ReadyProtect dashboards

Per-store security dashboards and digests show what the firewall is blocking and how your store's protection is performing.

Managed infrastructure

Delivered over a Cloudflare CDN on managed infrastructure - patching, hardening and uptime are our responsibility, not a checklist we hand you.

Payments off your servers

Card payments run through established, PCI-DSS-compliant gateways such as Stripe and PayPal - sensitive card data never lands on your store.

Security shouldn't be a plugin. It's the platform.

See how ReadyCMS protects your store

Tell us about your setup and compliance requirements, and we'll walk you through the firewall, the application hardening and the data tooling - on your real store.

Book a demoTalk with usNo credit card. No commitment.