ISO 27001: data security in webshop connectors

A customer places an order in your webshop. Within a few seconds a stream of data flows to Exact Online: name, address, e-mail address, phone number. In addition there are the order details, products, amounts, VAT calculations and any discounts.

ISO 27001 gecertificeerde veilige webshop koppeling

What actually flows through your connector

A customer places an order in your webshop. Within a few seconds a stream of data flows to Exact Online: name, address, e-mail address, phone number. Alongside that the order details, products, amounts, VAT calculations and any discounts. And with the payment: bank account number and payment method.

That is not abstract data. It is personal data covered by the GDPR, combined with financial information that leaves your company vulnerable if it ends up in the wrong hands.

Most entrepreneurs think of convenience when they consider a webshop connector: processing orders automatically, syncing stock, creating invoices without retyping. Rightly so. But every connector is also a conduit for sensitive information. And the security of that conduit deserves at least as much attention as the functionality.

The risk nobody sees, until it is too late

A secure webshop connector is not a luxury. It is a necessity. Yet security is rarely the first thing entrepreneurs ask about when choosing a connector supplier. The focus is on features, price and speed of implementation. Understandable, but risky.

What can go wrong with a poorly secured connector? Customer data sent unencrypted between systems. Login details stored on an unsecured server. An API connection without proper authentication, allowing malicious parties access to your administration.

The consequences are not theoretical. Data breaches cost SMEs tens of thousands of euros in direct damage on average, not counting fines from the Dutch Data Protection Authority. But the biggest damage is often the trust you lose with your customers. You do not earn that back with an apology e-mail.

The CIA triad: three pillars of data security

ISO 27001, the international standard for information security, is built on three principles known as the CIA triad.

Confidentiality. Only authorised people and systems may have access to the data. Customer data that flows through your connector must be unreadable to anyone except the sender and the receiver.

Integrity. Data must not be altered in transit. If an order with three products leaves your webshop, three products must arrive in Exact Online, not two, not four, and not three with a different amount.

Availability. The connector must work when you need it. A security measure so strict that your connector fails regularly defeats its own purpose.

These three pillars sound obvious. The difference lies in whether a supplier actually safeguards them structurally, or merely mentions them on a website.

How iWebDevelopment approaches security structurally

At iWebDevelopment, information security is not a side issue and not a marketing story. It is an ongoing process that is checked every year by an independent auditor.

ISO 27001 certification

iWebDevelopment is ISO 27001 certified. That means the entire information security policy, from access control to incident management, meets the strictest international standard. Not once, but continuously. Every year an external audit takes place to check whether all processes, systems and procedures still meet the standard.

ISO 27001 is not a checkbox. It forces an organisation to identify risks systematically, take measures and continuously evaluate those measures. That is the difference between a company that says it is secure and a company that can prove it.

Independent pentest

Besides the annual audit, iWebDevelopment has independent penetration tests carried out by an external security firm. That firm tries to find vulnerabilities in the systems and connectors using the same techniques as malicious hackers.

The goal is not to confirm that everything is secure. The goal is to find weak spots before someone else does. Any findings are addressed and resolved immediately.

Bank-level encryption

All data that flows between your webshop and Exact Online is encrypted with AES-256 encryption, the same standard banks use for internet banking. Both data in transit (moving between systems) and data at rest (stored on servers) is encrypted.

Even if someone managed to intercept the data traffic, the information would be unreadable without the correct keys. That applies to customer data, order data and financial information.

EU-hosted, encrypted, under your control

Our infrastructure runs entirely in the EU, ISO 27001 certified and encrypted at rest and in transit. Webshop connectors work as a secure conduit: orders flow from your webshop to Exact Online without lingering anywhere in between. For analytics connectors we set up a private environment per administration, shielded and managed by you. You decide who can access it and you can revoke any connector at any time.

That minimises the attack surface. There is simply no database with bank details or invoice amounts that can be stolen.

Official Exact Online partnership

iWebDevelopment is an official partner of Exact Online. That partnership is not purely commercial, as Exact sets concrete security requirements for partners who gain access to their API. By meeting those requirements, the connector is built according to the guidelines Exact itself uses to protect customer data.

The partnership also means direct communication about API changes or security updates. No surprises, no overdue maintenance.

The GDPR component

Since the introduction of the GDPR in 2018, you as an entrepreneur are responsible for protecting personal data, even when you outsource that processing to a software supplier. A connector that processes customer data without adequate security is not only a technical risk. It is a legal risk.

When choosing a connector supplier it is wise to ask about a data processing agreement, the security policy and any certifications. An ISO 27001 certificate gives you as an entrepreneur the assurance that the supplier meets an internationally recognised standard, something you can present during a GDPR check.

What to watch out for with other providers

Not every connector supplier invests in security at this level. When comparing providers there are a few questions you can ask.

Does the provider have an ISO 27001 certification or similar certification? Is an independent pentest carried out regularly? How is data encrypted, both in transit and at rest? Where is data stored, and for how long? Is a data processing agreement available?

The absence of answers to these questions is an answer in itself.

Cancellable monthly, your data stays yours

Security is also about control. At iWebDevelopment the connector can be cancelled monthly. There is no annual contract that ties you down, no vendor lock-in that forces you to stay. And because no financial data is stored on our own servers, you do not have to worry about what happens to your data when you cancel.

Your data flows from your webshop to Exact Online. It stays yours. Always.

Trust starts with choosing a secure connector

A webshop connector with Exact Online must above all work reliably. But reliability without security is like a front door that is always open. It works, but it does not feel right.

ISO 27001 certification, independent pentests, AES-256 encryption and an official Exact Online partnership are not selling points. They are basic requirements for a connector that you entrust with your customer data.

Curious what a secure webshop connector looks like in practice? Schedule a demo and discover how the security works behind the scenes.

Want a secure connector? View our webshop connectors →