Last updated 10 August 2026
Security
Upsell Pilot uses tenant-bound Shopify authentication, encrypted credentials, isolated production services, durable jobs, explicit write boundaries, and reversible changes.
Platform controls
Embedded requests are authenticated with Shopify session tokens. Webhook HMAC is verified before tenant lookup. Browser and API operations derive the shop from the authenticated server context.
Data protection
Access and refresh tokens are encrypted at rest with a dedicated key. PostgreSQL, web, worker, and scheduler services are isolated from other Fleeta apps. Logs redact secrets and direct customer identifiers.
Safe changes
Before a Shopify mutation, Upsell Pilot stores a pre-change snapshot and operation token. Once the external-write boundary is crossed, unknown outcomes require reconciliation and are never blindly replayed.
Reporting
Report suspected vulnerabilities privately to vytautas@fleeta.co.uk. Include reproduction steps without accessing another merchant's data.