IoneShop
Site versionFor shops

IoneShop · Enterprise Secure

Enterprise Secure — program catalogue and terms

1. Why Enterprise Secure exists

Large merchants, chains and holdings need more than “store hosting”: clear shared responsibility, an Incident path, evidence for diligence/NIS2-oriented operations, and optional insurance-process support.

Enterprise Secure is a program layer added to the IoneShop Platform:

ProgramAbbrev.For whom
Cyber Protection ProgramCPPongoing Platform-layer protection
Incident ResponseIRreaction and escalation on Incidents
Cyber Risk AssessmentCRAconfiguration / shared-responsibility review
Forensics SupportFSlog preservation and forensic vendor cooperation
Incident Cover AssistICAinsurance-process support / loss documentation

The full Secure pack is typically offered with the Enterprise plan; individual modules may be added to Platform (per Order Form).

AreaProvider (IoneShop)Customer
Tenant isolation, TLS, Platform hardeningYes
SaaS-layer monitoring and IRYes (when IR/CPP)Contact-point cooperation
Store config, rules, staff API keysCRA advisoryResponsibility
Customer PSP, ESP, ERP, WMS, CDNIntegration per SOWResponsibility
B2C legal texts, Shopper VATOptional templatesResponsibility
Customer cyber policyICA supportPolicyholder (unless OF differs)

3. Cyber Protection Program (CPP)

Product promise: the Platform is maintained under protection adequate to multi-tenant SaaS risk.

Scope (examples):

Out of scope:

Deliverables: control overview (security overview), status/Incident channel, periodic report if in Order Form.

4. Incident Response (IR)

Product promise: when something goes wrong on the Platform — someone answers, there is a playbook and communication.

Scope:

Out of scope:

Legal principle: IR is delivered with due professional care; it is not a guarantee of outcome (“zero harm”).

5. Cyber Risk Assessment (CRA)

Product promise: once per period (e.g. quarter / year) — workshop + report: what sits on the Platform side, what on the Customer side, where configuration gaps exist.

Scope:

Out of scope:

Legal principle: CRA is advisory. Customer accepts residual risk decisions.

6. Forensics Support (FS)

Product promise: on suspected breach — we do not erase traces: Platform logs are preserved within the retention window and we cooperate with forensic firms.

Scope:

Out of scope:

Fees: hours beyond pack — per Order Form rate card; P1 priority may have higher rate.

7. Incident Cover Assist (ICA) — insurance-process support

Incident Cover Assist means support around the insurance process and Incident documentation — not an automatic policy or indemnity payment by the Provider.

The Provider is not an insurer. ICA is operational and documentation assistance; policy terms are governed solely by the Customer’s insurer (or partner named in the Order Form).

Variants (selected in Order Form):

VariantCustomer receivesWe do not promise
ICA-DocsHelp with documentation for Customer policy + Incident timelineIndemnity payments
ICA-BrokerIntroduction to broker / partner facilityThat a policy will be issued / renewed
ICA-FacilityParticipation in group facility (when active) — terms = insurer policy wordingThat Provider is the insurer
ICA-CreditProvider service credit / reaction fund up to OF amountFull business loss coverage
  1. ABSGROUP INC. is not an insurance undertaking unless the Order Form expressly states otherwise in writing.
  2. Insurer denial does not create Provider liability beyond Enterprise Terms Section 14 limits (Secure sub-cap: 100% of Secure fees / 12 months).
  3. Customer must maintain its own insurance adequate to its risk if compliance requires it — Secure does not replace it.

8. Packaging

PackSuggested contentsPlan
Secure CoreCPP + IR (extended business hours)Platform+
Secure PlusCore + CRA (1×/year) + elevated FS retentionEnterprise
Secure MaxPlus + 24/7 IR + ICA (Docs or Facility) + mandatory PIR after P1Enterprise

Pack names in Order Form may be customised; scope always = SOW checklist.

9. Limits, exclusions, Provider security

  1. Secure liability: sub-cap in Enterprise Terms Section 14 — 100% of net Secure module fees in the 12 months preceding the event (unless Order Form differs).
  2. Exclusions: Customer / Customer staff fault, lack of IR cooperation, unapproved tests, Force Majeure, third-party actions outside Provider control.
  3. Customer must not publish that “IoneShop guarantees our NIS2 compliance” or “we are insured by IoneShop” unless ICA-Facility and policy wording allow it.
  4. Secure does not authorise public penetration tests of the Platform without written consent (window, scope, NDA).

10. How to buy

  1. Demo / Secure scope workshop.
  2. Order Form: pack + Capacity Band + SLA + DPA.
  3. Kick-off: IR contacts, channels, log retention.
  4. First CRA within T+30/90 days (if in pack).

Contact: [email protected]

DocumentPath
Enterprise Terms/enterprise/terms
SLA annex/enterprise/sla
Enterprise Privacy/enterprise/privacy
Enterprise Cookies/enterprise/cookies
Shop terms/terms

*IoneShop Enterprise Secure 1.1-secure. Not legal advice or an insurance policy.*

Related documents

Back to Enterprise

Enterprise Secure · IoneShop