Security begins with visible product boundaries.
A transparent overview of Shopify permissions, staging, tenant isolation, token handling, access revocation and incident reporting.
A transparent overview of theme permissions, token protection, tenant scoping and operational boundaries.
A public security overview, not an unsupported certification claim.
This page documents current product boundaries and operating controls. TaskerArmy should not imply SOC 2, ISO 27001 or another certification until it has been completed and can be evidenced.
Permissions must match theme engineering.
OAuth scopes, app listing text, privacy disclosures and the actual code configuration must remain synchronized. Unnecessary customer and order scopes should not be requested.
Every store and job is scoped to an authorized tenant.
Authorization checks should be enforced server-side for stores, themes, jobs, files, previews, billing and MCP context.
Tokens and secrets stay outside logs and generated output.
Use protected environment configuration, encrypted storage where applicable, least-privilege service access and explicit rotation or revocation procedures.
Approval, activity history and support access remain attributable.
Administrative support access should be logged. Impersonation or troubleshooting tools must show actor, tenant, purpose and time.
Internal infrastructure belongs in a subprocessor or privacy disclosure—not the integrations marketplace.
Email, billing, hosting, database and model providers should be listed where legally and operationally relevant without presenting them as customer-configurable product integrations.
Make suspected incidents easy to report without sharing secrets.
Provide a monitored security contact, acknowledge reports, preserve evidence and communicate confirmed impact and remediation with appropriate customers.
Backups, deployment controls and recovery procedures support resilience.
The marketing site and product require separate availability, recovery and incident procedures. Public status reporting should move to a monitored status service.
Related TaskerArmy pages
Direct answers before installation
Does TaskerArmy edit the live theme automatically?
No. Theme changes are prepared and reviewed on staging. Production remains an explicit merchant-controlled decision.
Does TaskerArmy access customer or order data?
The product is designed around theme engineering. Current permissions should be verified against the live Shopify app configuration, and unnecessary customer or order scopes should not be requested.
What happens when the work is too complex?
TaskerArmy should refuse, pause or escalate work that cannot be completed safely as a bounded job. Complex architecture and consulting can be routed to Shugert or the merchant’s existing team.
Connect the store. Start with evidence.
Run the connected-store audit, review prioritized findings and decide which bounded engineering job should move to staging first.