Separate workspace boundaries
Every organization has its own identifier, membership, and role checks. Sensitive server operations scope database access to the authenticated workspace, with negative tests for cross-workspace access.
ShopOps combines organization-scoped authorization, managed identity, encryption, additional protection for financial connections, controlled providers, and tested release safeguards.
Every organization has its own identifier, membership, and role checks. Sensitive server operations scope database access to the authenticated workspace, with negative tests for cross-workspace access.
Auth0 provides ShopOps identity. Owners, staff, partners, and administrators receive only the functions their role allows. New accounts do not inherit access to existing workspaces without an authorized invitation.
Creating, exchanging, repairing, or disconnecting a financial connection requires an authenticated owner and proof of multi-factor authentication. The server denies the action if that proof is absent.
Production traffic uses managed HTTPS. Cloudflare encrypts database and object-storage data at rest. Plaid access tokens are additionally encrypted with AES-GCM before storage and are scrubbed after disconnect.
Plaid connections can return data for review but cannot initiate transfers. ShopOps never receives a bank password, and imported activity does not change financial totals until an authorized person confirms it.
Changes pass linting and automated security/regression tests. Dependency, source, and secret checks run on changes and weekly. Critical findings require immediate containment and a 24-hour remediation or shutdown target.
Versioned consent records the owner’s decision before a new bank connection. Raw Plaid data is deleted after successful disconnect. Workspace owners can export records and start a reviewed permanent-deletion process.
A documented process covers containment, evidence preservation, investigation, recovery, required notification, and corrective action. Suspected credential or data exposure is treated as urgent.
Email william@integritydrivetrain.com. Do not include passwords, financial-institution credentials, recovery codes, API keys, or live customer exports. If the concern involves active credential exposure, revoke or rotate that credential first when safe to do so.