Security and vulnerability reporting

Report suspected vulnerabilities privately to security@buyerprism.com. Include a clear description, reproduction steps, affected shop/app surface, and impact. Do not include live credentials or personal data. Do not test against stores you do not own or have written authorization to assess.

The operator should acknowledge credible critical reports within one business day, preserve evidence without copying merchant payloads, rotate affected secrets, contain access, notify affected parties where required, and publish a remediation timeline after triage.

The application uses read-only Shopify scopes, a runtime GraphQL mutation guard, encrypted server-side offline tokens, authenticated Shopify webhooks, strict tenant scoping, private application/cache networks, TLS, managed secrets, dependency scanning, deployment rollback, and alerts for rejected mutation attempts, webhook verification failures, unhealthy targets, HTTP 5xx responses, and failed deletion cleanup.