Legal
Security
Last updated: August 17, 2026
What we protect, how we protect it, and what we deliberately don't hold.
We can't lose what we don't hold
The Shopify connection is zero-credential. We read your storefront's public catalog JSON. There is no API key, no OAuth token, no admin access, and no write access.
We don't see your orders, your buyers, or your payment data. Card details go straight to Stripe and don't touch our servers.
Transport and storage
All traffic runs over TLS, with HSTS enabled. Database connections require TLS.
Files, which means your product images and the evidence captures, live in Cloudflare R2. Access goes through signed storage URLs that expire within minutes. Databases and object storage are encrypted at rest at the volume level by our infrastructure providers.
Authentication and sessions
Passwords are hashed with bcrypt and are never stored in plain text. Sessions are database-backed and revocable, and they are held in signed, HttpOnly, SameSite cookies that are secure-only in production.
Sign-in, registration, and password reset are rate limited. Passwords and tokens are filtered out of application logs.
Tenant isolation
Every query in the product is scoped to your company on every request. Support staff access is restricted, and enforcement-related actions are written to an append-only audit log.
Humans gate enforcement
A takedown cannot send itself. Every enforcement action needs your explicit approval, then a second review by our staff before release. Behind that sit a kill switch and send caps.
It is the reason an error in our pipeline cannot become a filed claim.
Development practices
Static security analysis (Brakeman) and dependency vulnerability scanning run in CI on every change. Secrets are never committed to the repository.
Where we fall short today
We are a small company and we will not pretend otherwise. Two-factor authentication is not available yet. We hold no SOC 2 or similar certification.
If your review requires either one, tell us. It shapes our roadmap.
Report a vulnerability
Email [email protected] and we will acknowledge it within two business days. We do not run a public bounty program.