Security & privacy
Enterprise-grade security for virtual try-on
Tryonixs is built to protect merchants, developers, and shoppers. From client-side face processing and encrypted connections to API key allowlisting and row-level data isolation — security is part of the platform, not an afterthought.
On-device AI
Face tracking runs in the browser
Domain allowlists
Public keys locked to your domains
RLS isolation
Each merchant sees only their data
HTTP-only sessions
Secure dashboard authentication
CSP headers
Hardened production responses
HTTPS required
Camera access on secure origins
Platform security
How Tryonixs protects your business
Every layer — from the embeddable SDK to the merchant dashboard — is designed with defense in depth.
Client-side face processing
Face landmarks are detected in the shopper's browser using on-device AI. Camera frames are not uploaded to Tryonixs servers for rendering or tracking.
HTTPS everywhere
Tryonixs, the SDK, merchant product assets, and API requests are designed to run over TLS. Camera access requires a secure context in modern browsers.
Public API keys & domain allowlists
Only browser-safe public keys (pk_live_) belong in storefront code. Each key can be restricted to approved merchant domains to prevent unauthorized use.
Row-level data isolation
Merchant accounts, analytics, and configuration are protected with PostgreSQL Row Level Security so each store can only access its own data.
Secure authentication
Dashboard sessions use HTTP-only cookies with Supabase SSR. Admin access is separately gated with additional environment allowlist checks.
Content Security Policy
Production responses include strict security headers — CSP, HSTS, frame controls, and referrer policies — tuned for Tryonixs and embeddable try-on routes.
Shopper privacy
Respectful camera experiences
Virtual try-on should feel safe. Tryonixs prioritizes permission, transparency, and local processing.
Shoppers stay in control. Camera access is requested only when they choose to try on a product, and face inference happens on their device for responsive previews without sending video to external servers.
Permission-based camera access
Try-on opens only after a clear shopper action. The browser permission dialog is never triggered on passive page load.
No face template storage by default
Tryonixs is architected so face tracking runs locally. We do not store biometric face templates from try-on sessions unless you configure additional analytics.
Transparent data practices
Merchants remain responsible for their storefront privacy disclosures. Tryonixs provides a privacy-first foundation and clear documentation for compliance teams.
Merchant controls
Secure integrations for your storefront
Developers get clear patterns. Security teams get auditable controls.
Origin validation
SDK postMessage communication validates trusted origins to reduce cross-site embedding risks.
Subscription verification
Live SDK requests validate API keys and subscription status before opening try-on for new products.
Secure image proxy
Merchant CDN assets can be fetched through a controlled image proxy to avoid exposing credentials in the browser.
Dashboard isolation
Merchant dashboards and admin routes are excluded from public indexing and protected behind authentication.
Analytics boundaries
Session analytics are linked to your store account — not shared across merchants.
Secret key protection
Administrative and service credentials never belong in client-side JavaScript or theme snippets.
Enterprise
Enterprise security for larger rollouts
Retailers and brands with procurement requirements can work with Tryonixs on dedicated infrastructure, custom contracts, and security review support.
Contact sales for security review- Dedicated infrastructure options
- Custom domain and white-label deployments
- SLA-backed support and onboarding
- Security review and procurement assistance
- Multi-store and team access controls
- Custom data retention discussions
FAQ
Security questions
Common questions from developers, merchants, and compliance teams.
- Does Tryonixs upload shopper camera video to the cloud?
- No. Face detection and virtual try-on rendering run client-side in the browser. Tryonixs does not receive raw camera video for standard try-on sessions.
- How are API keys protected?
- Use public keys (pk_live_) in your storefront. Restrict each key to approved domains in the Tryonixs dashboard. Never expose secret or service credentials in frontend code.
- Is Tryonixs GDPR-friendly?
- Tryonixs is designed with privacy-first architecture — local face processing, permission-based camera access, and merchant-controlled analytics. Review our Privacy Policy and consult your legal team for your specific obligations.
- What security comes with Enterprise plans?
- Enterprise customers can discuss dedicated infrastructure, white-label deployments, SLA support, custom integrations, and procurement security reviews with our sales team.
- How do I report a security issue?
- Contact us at hello@tryonixs.com with reproduction steps and impact details. We take security reports seriously and will respond as quickly as possible.
Need a security questionnaire completed?
Our team can help with vendor assessments, integration reviews, and enterprise procurement. Include your platform, domains, and timeline when you reach out.
Official Tryonixs social profiles
Follow Tryonixs for product updates, integration guides, and platform news.
