security + ownership

keep the boundary clear.

Horcrux runs the commerce operation. Your business owns its brand, records and shopper-money relationships. Every external dependency has to earn its place with evidence.

shopper payment

merchant-owned

Horcrux holds no shopper funds and takes no transaction fee. An optional online-payment path requires the merchant’s own approved provider account and separate evidence.

platform billing

manual verification

Horcrux subscriptions use monthly invoices settled by manual bank transfer or bKash Send Money. There is no automatic charge or auto-renewal.

fulfilment

manual now

Manual fulfilment is available. Named courier connections remain evidence-gated until current merchant-owned access and real flows are exercised.

operating controls

ownership is a set of decisions.

The useful question is not whether a platform says “secure.” It is where the data, authority and responsibility sit.

01

Tenant boundary

Stores, records, media, jobs and exports stay scoped to the merchant tenant.

02

Team boundary

Individual verified-email accounts use five built-in staff roles and store-scoped permissions.

03

Recovery boundary

Dashboard, data and exports remain available during paid nonpayment; closure and deletion have explicit recovery rules.

04

Evidence boundary

A mock, package or marketing statement never upgrades a provider or capability to launch-ready.

what is not claimed

proof before promotion.

  • 01 Merchant-owned online payment is optional and evidence-gated; COD is the launch-ready checkout path.
  • 02 Named courier connections are not partnerships or launch-ready integrations. Manual fulfilment is available.
  • 03 Custom roles are not currently activated, and custom storefront Beta does not yet promise builds or deployment.
  • 04 No certifications, SLA, automatic billing, AI or PostHog product-telemetry claims are made here.
next step

ask for a place in the operation.