> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokensupply.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and your data

> How keys are protected, how delivery links stay private, and how each store's data is kept separate.

Digital keys are valuable, so the platform is built to protect them at every step. This page explains, in plain terms, how keys are kept safe, how buyer links stay private, and how your store's data is walled off from everyone else's.

## Keys are protected at rest

Your keys are stored in a protected form, not as plain readable text. They are not exposed as they move through the system, and they are masked in ordinary screens and lists. A real key value appears in only a few deliberate places:

* When the buyer who bought it reveals it on their own delivery page.
* When a teammate who can manage inventory clicks to reveal one key in your inventory screen. Each of these reveals is recorded in that key's activity history.
* In a delivery email, but only if you chose to put keys in your delivery template. By default the email carries a private link instead.

<Warning>
  Most of your team never needs to see a raw key to run your store. Keep inventory Manage access to the people who need it, since those are the teammates who can reveal keys.
</Warning>

## Delivery links stay private

A buyer collects their keys through a private link. That link alone identifies their order, so there is no login for the buyer to manage. The link is long and unguessable, it is created only at delivery time, and it opens only on your store's own web address, never on the admin app.

<Steps>
  <Step title="The link is unique and hard to guess">
    Each order gets its own private link that cannot be worked out from another one.
  </Step>

  <Step title="It only works in the right place">
    The link opens on your store's surface and nowhere else, so it cannot be used against the admin app.
  </Step>

  <Step title="It reveals one order only">
    Holding the link shows just that buyer's order, and keys stay masked until they choose to reveal them.
  </Step>
</Steps>

## Each store's data is separate

Every store's data is kept apart from every other store's. When you are signed in, you only ever see and touch data for the store you are currently in, and roles further limit what each teammate can reach inside that store. Invites are tied to the email address they were sent to, so only that person can use one to join your store.

<Note>
  This separation is enforced by the platform itself, not left to chance. Data is always tied to the store it belongs to, and requests are checked against both the store and the teammate's permissions before anything is shown or changed.
</Note>

<CardGroup cols={2}>
  <Card title="Security guide" icon="shield" href="/guides/security/security">
    Practical steps to keep your store secure.
  </Card>

  <Card title="Accounts and roles" icon="users" href="/how-it-works/accounts-and-roles">
    How permissions limit what teammates can do.
  </Card>

  <Card title="Stores and multi-tenancy" icon="store" href="/how-it-works/stores-and-multi-tenancy">
    How each store's data stays separate.
  </Card>

  <Card title="Delivery and custom domains" icon="globe" href="/how-it-works/delivery-and-custom-domains">
    Where buyer delivery pages are hosted.
  </Card>
</CardGroup>
