Industry
Technology and security for retail and e-commerce
Retail platforms face automated fraud around the clock and earn most of their revenue on a few peak days. Onion Infosec builds commerce systems, scales them in cloud and secures checkout, accounts and stores.
- Sector
- Retail & E-commerce
- Segments
- Online retail, Marketplaces, Store and omnichannel retail, Direct-to-consumer brands
01Context
E-commerce platforms face a continuous, automated adversary.
Card testing, credential stuffing, scalping bots and payment fraud run around the clock. Margins are thin, so fraud losses and the friction caused by false positives both cost revenue.
Revenue concentrates on peak trading days, when downtime is most expensive and change is most risky. Storefronts depend on third-party scripts, payment providers, logistics integrations and marketing tools, each of which can alter what a customer’s browser runs. Store networks add point-of-sale systems and seasonal staff to the picture.
02Technology
What the sector builds and runs.
- Commerce platforms and apps
- Storefronts, mobile apps, checkout, order management and headless commerce builds, with performance treated as a feature.
- Cloud scaling and reliability
- Autoscaling, load testing before peak events, observability and cost control so capacity follows demand.
- AI for search, service and forecasting
- Product search, recommendations, customer service assistants and demand forecasting, with controls on how customer data is used.
- Store and corporate IT
- Point-of-sale environments, store networks, endpoints and identity for seasonal staff, with 24×7 support during trading hours and beyond.
03Risk
The risks that matter most.
- Account takeover at scale
- Credential stuffing against customer accounts that hold saved cards, addresses and loyalty value.
- Payment page attacks
- Skimming scripts, checkout manipulation and card-testing traffic directed at payment flows.
- Availability attacks at peak
- DDoS and extortion timed to the trading days when an outage costs the most.
- Third-party scripts and integrations
- Tag managers, plugins, marketplaces and logistics connections that run code or hold tokens inside the storefront.
04Regulation and assurance
What you may need to demonstrate.
PCI DSS governs cardholder data, and version 4 adds specific requirements for scripts on payment pages. GDPR and the ePrivacy rules in Europe and CCPA in California govern customer data and tracking. PSD2 requires strong customer authentication for many EU payments. Regional examples include the DPDP Act and RBI card tokenization rules in India. Marketplaces that sell to enterprises are also asked for SOC 2 or ISO 27001.
Which of these apply depends on where you operate and what you do. We scope against your actual obligations.
05Where we usually start
Services that matter most here.
Application security
Testing and design review for checkout, account and promotion logic, plus control of third-party scripts on payment pages.
Software and product development
Storefront, mobile and order management engineering with security testing in the release pipeline.
Cloud engineering
Infrastructure that scales for peak events, tested under load beforehand, with DDoS protection and cost visibility.
Managed SOC and MDR
24×7 monitoring tuned to account takeover, bot traffic and payment anomalies.
AI
Search, recommendation and customer service systems built with consent-aware data use and evaluation before release.
Identity security
Customer authentication that resists credential stuffing, and workforce identity for store, warehouse and seasonal staff.
