Security
What is implemented, and what is not claimed.
- 01
Access and identity
Users are authenticated through Shopify. Requests are scoped to the store they came from, and every record and stored file carries the store it belongs to.
- 02
Files
Object storage is private. Downloads are authorised on the server and issued as short-lived links.
- 03
Uploads
File type is checked by content, not by extension. Type, size and page limits are enforced before parsing, and spreadsheets are checked for formula injection on export.
- 04
Webhooks
Shopify webhooks are verified by HMAC and deduplicated by webhook ID before any work is queued.
Reporting a problem
Report a suspected vulnerability through the contact page and we will respond.
No third-party security certification has been completed. We do not display badges we have not earned.
We do not claim SOC 2, ISO 27001 or GDPR certification. No such certification has been obtained.