Security

Security should be specific enough to inspect.

TaskerArmy handles Shopify access tokens and theme code. This page documents the current design without claiming certifications the company has not completed.

01

Shopify access

The current app requests theme permissions for reading and writing themes. It does not request customer or order data for the theme-engineering workflow.

02

Credentials

Store access tokens are encrypted before storage. OAuth offline access is refreshed when required.

03

Tenant isolation

Application routes scope stores, sessions, changesets, audits, billing and MCP data by the authenticated tenant or team owner.

04

Deployment controls

Agent writes target staging. Production requires approval, QA conditions or a deliberate human override, plus a live-file drift check.

05

Responsible disclosure

Report suspected security issues to security@taskerarmy.com. Do not include sensitive credentials in the initial message.

Questions

What merchants ask before installation.

Is TaskerArmy SOC 2 certified?

No SOC 2 claim is made on this site. Security maturity and future assurance work are tracked on the roadmap.

Does TaskerArmy store customer data?

The theme-engineering app does not request Shopify customer or order scopes. Account and operational data are stored to provide the service.