Security & residency
Built EU-first, and honest about it.
Leira is designed around a simple stance: keep your data in Europe, encrypt it, verify it, and never hold anything personal about your customers.
EU data residency
Metadata lives in an EU-region database and backups in EU-jurisdiction object storage. There is no US data path anywhere in the pipeline — your store's data never crosses the Atlantic.
Encrypted at rest
Every backup and every stored access token is sealed with AES-256-GCM. Encryption keys are held separately from the OAuth credentials, so rotating one never exposes the other.
No personal data, by design
Leira never requests order or customer scopes. That keeps it at Protected Customer Data Level 0/1 — your shoppers' personal information simply never reaches our servers.
Verified backups
A backup that claims success is re-read from a random sample and checked before it's marked verified — so you find out a backup is good now, not when you need it.
Every restore is reversible
Before any restore, Leira automatically takes a fresh safety snapshot. Combined with a field-level diff and dry-run, that means a restore can always itself be undone.
Least privilege access
Leira asks only for the scopes it actually uses to back up and restore products and themes. Off-site copies (Plus) push to your own storage with write-only credentials.