Industry

Technology and security for retail and e-commerce

Retail platforms face automated fraud around the clock and earn most of their revenue on a few peak days. Onion Infosec builds commerce systems, scales them in cloud and secures checkout, accounts and stores.

Sector
Retail & E-commerce
Segments
Online retail, Marketplaces, Store and omnichannel retail, Direct-to-consumer brands

01Context

E-commerce platforms face a continuous, automated adversary.

Card testing, credential stuffing, scalping bots and payment fraud run around the clock. Margins are thin, so fraud losses and the friction caused by false positives both cost revenue.

Revenue concentrates on peak trading days, when downtime is most expensive and change is most risky. Storefronts depend on third-party scripts, payment providers, logistics integrations and marketing tools, each of which can alter what a customer’s browser runs. Store networks add point-of-sale systems and seasonal staff to the picture.

02Technology

What the sector builds and runs.

Commerce platforms and apps
Storefronts, mobile apps, checkout, order management and headless commerce builds, with performance treated as a feature.
Cloud scaling and reliability
Autoscaling, load testing before peak events, observability and cost control so capacity follows demand.
AI for search, service and forecasting
Product search, recommendations, customer service assistants and demand forecasting, with controls on how customer data is used.
Store and corporate IT
Point-of-sale environments, store networks, endpoints and identity for seasonal staff, with 24×7 support during trading hours and beyond.

03Risk

The risks that matter most.

Account takeover at scale
Credential stuffing against customer accounts that hold saved cards, addresses and loyalty value.
Payment page attacks
Skimming scripts, checkout manipulation and card-testing traffic directed at payment flows.
Availability attacks at peak
DDoS and extortion timed to the trading days when an outage costs the most.
Third-party scripts and integrations
Tag managers, plugins, marketplaces and logistics connections that run code or hold tokens inside the storefront.

04Regulation and assurance

What you may need to demonstrate.

PCI DSS governs cardholder data, and version 4 adds specific requirements for scripts on payment pages. GDPR and the ePrivacy rules in Europe and CCPA in California govern customer data and tracking. PSD2 requires strong customer authentication for many EU payments. Regional examples include the DPDP Act and RBI card tokenization rules in India. Marketplaces that sell to enterprises are also asked for SOC 2 or ISO 27001.

  • PCI DSS
  • GDPR
  • CCPA
  • PSD2 strong customer authentication
  • ISO 27001
  • SOC 2
  • OWASP ASVS
  • DPDP Act

Which of these apply depends on where you operate and what you do. We scope against your actual obligations.