ISO 27001: data security in webshop connectors

A customer places an order in your webshop. Within a few seconds a stream of data flows to Exact Online: name, address, email address, phone number. Along with the order details: products, amounts, VAT calculations and any discounts.

ISO 27001 gecertificeerde veilige webshop koppeling

What actually flows through your connector

A customer places an order in your webshop. Within a few seconds a stream of data flows to Exact Online: name, address, e-mail address, phone number. On top of that the order details: products, amounts, VAT calculations, any discounts and the payment details, and depending on the chosen method an IBAN or card data as well.

That is not abstract data, it concerns personal details that fall under the GDPR, combined with financial information that leaves your company vulnerable if it ends up in the wrong hands.

Most entrepreneurs think of convenience when it comes to a webshop connector: processing orders automatically, synchronising stock, creating invoices without retyping. That is why you buy the connector. But this convenience also creates a channel for sensitive information. And securing it deserves at least as much attention as the functionality.

Invisible risks

A secure webshop connector is not a luxury, it is a necessity. Yet security is rarely the first thing entrepreneurs ask about when choosing a connector supplier. The focus is on the features, price and speed of implementation.

What can go wrong with a poorly secured connector? Customer data sent unencrypted between systems, login credentials stored on an unsecured server, you would rather not think about what happens if this data leaks. Or an API connection without proper authentication, giving malicious parties access to your administration.

These are not theoretical consequences, data breaches cost SMEs tens of thousands of euros in direct damage on average, quite apart from fines from the Dutch Data Protection Authority. But the biggest damage is often the trust you lose with your customers, and you will not win that back with an apology e-mail.

The CIA triad: three pillars of data security

ISO 27001, the international standard for information security, is built on three principles, known as the CIA triad.

Confidentiality: Only authorised people and systems may have access to the data. Customer data flowing through your connector must be unreadable to everyone except the sender and the recipient.

Integrity: Data must not be altered along the way. If an order with three products leaves your webshop, three products must arrive in Exact Online with the agreed amount.

Availability: The connector must work when you need it. A security measure so strict that your connector fails regularly defeats its own purpose.

These three pillars sound obvious. The difference lies in whether a supplier genuinely safeguards them on a structural basis or merely mentions them on a website.

How iWebDevelopment tackles security structurally

At iWebDevelopment, information security is not an afterthought and not a marketing story. It is an ongoing process that is checked every year by an independent auditor.

ISO 27001 certification

iWebDevelopment is ISO 27001 certified. This means the entire information security policy, from access control to incident management, meets the strictest international standard. This is continuously monitored, and every year an external audit takes place to check whether all processes, systems and procedures still comply with the standard.

ISO 27001 is not a checkbox. It forces an organization to identify risks systematically, take measures and continuously evaluate those measures. That makes the difference between a company that says it is secure and a company that can prove it.

Independent pentest

In addition to the annual audit, iWebDevelopment has independent penetration tests carried out by an external security agency. That agency tries to find vulnerabilities in the systems and connectors using the same techniques as malicious hackers.

The goal is not to confirm that everything is secure. The goal is to find weak spots before someone else does. Any findings are addressed and resolved right away.

Bank-level encryption

All data flowing between your webshop and Exact Online is encrypted with AES-256 encryption, the same standard banks use for online banking. Both data in transit (moving between systems) and data at rest (stored on servers) is encrypted.

Even if someone were to succeed in intercepting data traffic, the information is unreadable without the right keys. That applies to customer details, order data and financial information.

EU-hosted, encrypted, under your control

Our infrastructure runs entirely in the EU, is ISO 27001 certified and encrypted both during a transfer and when stored. Webshop connectors work as a secure pass-through: orders flow from your webshop to Exact Online without getting stuck anywhere in between. For analytics connectors we set up a private environment per administration, shielded and managed by you. You decide who has access and can revoke any connector at any moment.

That minimizes the attack surface. There is simply no database of bank details or invoice amounts that can be stolen.

Official Exact Online partnership

iWebDevelopment is an official partner of Exact Online. That partnership is not purely commercial, Exact sets concrete security requirements for partners who gain access to their API. By meeting those requirements, the connector is built according to the guidelines Exact itself uses to protect customer data.

The partnership also means direct communication about API changes or security updates. No surprises, no overdue maintenance.

The GDPR component

Since the introduction of the GDPR in 2018, you as an entrepreneur are responsible for protecting personal data, even when you outsource that processing to a software supplier. A connector that processes customer data without adequate security is not only a technical risk. It is a legal risk.

When choosing a connector provider it is wise to ask about a processing agreement, the security policy and any certifications. An ISO 27001 certificate gives you as an entrepreneur the assurance that the provider meets an internationally recognised standard, something you can present during a GDPR audit.

What to look out for with other providers

Not every connector provider invests in security at this level. When comparing providers there are a few questions you can ask.

Does the provider have an ISO 27001 certification or a comparable certification? Is an independent pentest carried out regularly? How is data encrypted during a transfer and on the server? Where is data stored and for how long? Is a processing agreement available? The absence of answers to these questions is an answer in itself.

Your data stays yours

Security is also about control. At iWebDevelopment the connector can be cancelled monthly. There is no annual contract that ties you down, no vendor lock-in that forces you to stay. And because no financial data is stored on our own servers, you do not have to worry about what happens to your data when you cancel.

Trust starts with the choice for a secure connector

A webshop connector with Exact Online must first and foremost work reliably. But reliability without security is like a front door that is always open, it works, but you do not feel comfortable with it.

ISO 27001 certification, independent pentests, AES-256 encryption and an official Exact Online partnership are the basic conditions for a connector to which you entrust your customer data.

Curious how a secure webshop connector looks in practice? Schedule a demo and discover how the security works behind the scenes.

Do you want a reliable and secure connector? View our webshop connectors →