Founded in 2013, SHOPLINE is one of Asia’s largest and fastest growing commerce Software-as-a-service and solution providers. The SHOPLINE platform offers a rich ecosystem of technologies, resources and partners that empowers merchants to succeed. Merchants leverage SHOPLINE’s omnichannel solutions for e-commerce, social commerce and point-of-sales to sell their products and services around the world. SHOPLINE is headquartered in Singapore with about 2000 employees operating globally.
As an international ecommerce platform operating under a software-as-a-service (SaaS) business model, providing a top-notch user experience for its merchants at both the business (B2B) and merchant (B2C) levels is crucial to SHOPLINE’s success.
For its merchants, this means guaranteeing secure, fast-performing services across nearly unlimited custom domains. As SHOPLINE grew, the logistics of administering and maintaining a rapidly growing number of white-label private websites — each requiring its own security certificate — became a logistical challenge.
“As we took on more merchant clients, we exposed the shortcomings of our original technical DNS and SSL management implementation,” says George Wu, SHOPLINE’s Operations Manager. “The cost and sheer effort involved in maintaining tens of thousands of SSL certificates for our business’ domains skyrocketed, making it difficult to focus on product growth.”
On the merchant side, performance was at the top of SHOPLINE’s list of concerns. With merchant users distributed globally, the merchant sites SHOPLINE hosted frequently experienced location-based performance issues.
“To provide our international merchants with a stable user experience and a frictionless onboarding process, we needed an access layer network with the widest possible coverage area,” explains Wu. “In the early stages of our growth, creating a reliable performance solution on our own was an unrealistic technical and financial challenge.” The sheer scope of SHOPLINE’s international operations is at the heart of the platform’s other core challenge — securing merchants, merchants, and its data centers against online threats like DDoS attacks, SQL injections, credential stuffing, and inventory hoarding bots. Stopping these threats was critical to avoiding data leaks and service disruptions while maintaining merchant trust.
“Cyber security has been a constant battle between attackers and our safety teams,” says Wu. “To maintain an effective security barrier against sophisticated threats on the public Internet, we needed to dedicate significant time and keep costly resources on alert against unexpected attacks.”
Evaluating the alternatives, only Cloudflare offered the balance of efficacy and affordability SHOPLINE was looking for. SHOPLINE turned to the Cloudflare connectivity cloud, a single-vendor solution that offered performance and security while simplifying SSL management issues.
“Cloudflare and its security teams have proven their expertise time and time again, most recently by thwarting HTTP/2 Rapid Reset, the world’s largest global cybersecurity attack to date,” says Wu. “Because Cloudflare only charges us for our traffic and we don't need to invest in additional hardware or personnel, it is our ideal security partner.”
With customizable domain configurations, rapid global SSL deployments, and SSL lifecycle management features, Cloudflare SSL for SaaS was practically tailor-made for SHOPLINE’s needs. SSL for SaaS simplified SHOPLINE’s merchant onboarding and enhanced the platform’s ability to provide the branded visitor experiences its merchants demanded.
“Cloudflare removed the friction from our merchant intake process,” says Wu. “Our in-house solution took a vendor at least seven steps to link and provision a store. Integrating SSL for SaaS reduced that to three.”
Besides streamlining its merchant-facing onboarding process, SSL for SaaS' automated SSL lifecycle management reduces SHOPLINE’s administrative workloads, minimizes operational costs, and ensures expired security certificates do not catch the company by surprise. The company also uses SSL for SaaS to guarantee its own domains — like shopline.com, myshopline.com, oneship.io and regional variants like shopline.hk, and shopline.my, — are always secure and up to date.
Using Cloudflare application services, specifically threat intelligence provided by the easy-to-deploy Cloudflare Web Application Firewall (WAF), SHOPLINE secures its visitors, merchants, websites, APIs, and data centers against automated threats on the public Internet. Blocking nearly 80 million monthly threats across SHOPLINE’s corporate and merchant-branded sites, Cloudflare gives the platform the performance and resiliency to withstand sophisticated and brute-force bot attacks.
“Cloudflare has raised the bar on how much malicious traffic our sites can withstand,” says Wu. “No matter how severe the attack is, Cloudflare identifies the source and automatically implements measures to protect our back-end services — after that it is business as usual, we don’t need to do anything.”
Previously, the company had a paid emergency team on standby. Using Cloudflare, SHOPLINE has re-assigned those resources to feature creation and business development roles.