Security & privacy

Enterprise-grade security for virtual try-on

Tryonixs is built to protect merchants, developers, and shoppers. From client-side face processing and encrypted connections to API key allowlisting and row-level data isolation — security is part of the platform, not an afterthought.

On-device AI

Face tracking runs in the browser

Domain allowlists

Public keys locked to your domains

RLS isolation

Each merchant sees only their data

HTTP-only sessions

Secure dashboard authentication

CSP headers

Hardened production responses

HTTPS required

Camera access on secure origins

Platform security

How Tryonixs protects your business

Every layer — from the embeddable SDK to the merchant dashboard — is designed with defense in depth.

Client-side face processing

Face landmarks are detected in the shopper's browser using on-device AI. Camera frames are not uploaded to Tryonixs servers for rendering or tracking.

HTTPS everywhere

Tryonixs, the SDK, merchant product assets, and API requests are designed to run over TLS. Camera access requires a secure context in modern browsers.

Public API keys & domain allowlists

Only browser-safe public keys (pk_live_) belong in storefront code. Each key can be restricted to approved merchant domains to prevent unauthorized use.

Row-level data isolation

Merchant accounts, analytics, and configuration are protected with PostgreSQL Row Level Security so each store can only access its own data.

Secure authentication

Dashboard sessions use HTTP-only cookies with Supabase SSR. Admin access is separately gated with additional environment allowlist checks.

Content Security Policy

Production responses include strict security headers — CSP, HSTS, frame controls, and referrer policies — tuned for Tryonixs and embeddable try-on routes.

Shopper privacy

Respectful camera experiences

Virtual try-on should feel safe. Tryonixs prioritizes permission, transparency, and local processing.

Shoppers stay in control. Camera access is requested only when they choose to try on a product, and face inference happens on their device for responsive previews without sending video to external servers.

Permission-based camera access

Try-on opens only after a clear shopper action. The browser permission dialog is never triggered on passive page load.

No face template storage by default

Tryonixs is architected so face tracking runs locally. We do not store biometric face templates from try-on sessions unless you configure additional analytics.

Transparent data practices

Merchants remain responsible for their storefront privacy disclosures. Tryonixs provides a privacy-first foundation and clear documentation for compliance teams.

Merchant controls

Secure integrations for your storefront

Developers get clear patterns. Security teams get auditable controls.

Origin validation

SDK postMessage communication validates trusted origins to reduce cross-site embedding risks.

Subscription verification

Live SDK requests validate API keys and subscription status before opening try-on for new products.

Secure image proxy

Merchant CDN assets can be fetched through a controlled image proxy to avoid exposing credentials in the browser.

Dashboard isolation

Merchant dashboards and admin routes are excluded from public indexing and protected behind authentication.

Analytics boundaries

Session analytics are linked to your store account — not shared across merchants.

Secret key protection

Administrative and service credentials never belong in client-side JavaScript or theme snippets.

Enterprise

Enterprise security for larger rollouts

Retailers and brands with procurement requirements can work with Tryonixs on dedicated infrastructure, custom contracts, and security review support.

Contact sales for security review
  • Dedicated infrastructure options
  • Custom domain and white-label deployments
  • SLA-backed support and onboarding
  • Security review and procurement assistance
  • Multi-store and team access controls
  • Custom data retention discussions

FAQ

Security questions

Common questions from developers, merchants, and compliance teams.

Does Tryonixs upload shopper camera video to the cloud?
No. Face detection and virtual try-on rendering run client-side in the browser. Tryonixs does not receive raw camera video for standard try-on sessions.
How are API keys protected?
Use public keys (pk_live_) in your storefront. Restrict each key to approved domains in the Tryonixs dashboard. Never expose secret or service credentials in frontend code.
Is Tryonixs GDPR-friendly?
Tryonixs is designed with privacy-first architecture — local face processing, permission-based camera access, and merchant-controlled analytics. Review our Privacy Policy and consult your legal team for your specific obligations.
What security comes with Enterprise plans?
Enterprise customers can discuss dedicated infrastructure, white-label deployments, SLA support, custom integrations, and procurement security reviews with our sales team.
How do I report a security issue?
Contact us at hello@tryonixs.com with reproduction steps and impact details. We take security reports seriously and will respond as quickly as possible.

Need a security questionnaire completed?

Our team can help with vendor assessments, integration reviews, and enterprise procurement. Include your platform, domains, and timeline when you reach out.

Contact Tryonixs

Official Tryonixs social profiles

Follow Tryonixs for product updates, integration guides, and platform news.

Contact us