Security & Policies
Recognizing official domains to avoid phishing, understanding support policies and response times, and other trust and safety resources.
Configure a Content Security Policy (CSP)
How to set up and enforce a Content Security Policy on your Foxy checkout to control which scripts, styles, and other resources are allowed to load.
Ecommerce security terms reference
Definitions of ecommerce security and payment terms — including 3-D Secure, AVS, and payment gateway terminology — used throughout Foxy's documentation.
Foxy's security and compliance certifications
How to verify Foxy's PCI DSS Level 1 Service Provider status and EU-U.S. Data Privacy Framework certification, request our Attestation of Compliance, and find copy/paste policy language for your own store.
Help Us Help You
An overview of our support policies: expected response times, what details speed up your request, what we can and can't help with, and how we handle sensitive information over email.
Our Official Domains & Public Code
We use a few different domains (both our own and 3rd parties) to host different pieces of the Foxy infrastructure and code. To prevent phishing and g...
PCI DSS and compliance requirements
What PCI DSS is, the different levels of compliance (SAQ A through D), and how to tell which requirements actually apply to your store when you process payments through Foxy.
Privacy and security considerations
An overview of privacy and security details worth knowing when running a store — how email addresses and cart contents can be exposed during checkout, receipt visibility, and safe ways to share sensitive data.