SOShopOpsSECURITY AT SHOP OPS

Protection is built around each business workspace.

ShopOps combines organization-scoped authorization, managed identity, encryption, additional protection for financial connections, controlled providers, and tested release safeguards.

Program effective August 25, 2026Read the privacy notice
01

Separate workspace boundaries

Every organization has its own identifier, membership, and role checks. Sensitive server operations scope database access to the authenticated workspace, with negative tests for cross-workspace access.

02

Central identity and least privilege

Auth0 provides ShopOps identity. Owners, staff, partners, and administrators receive only the functions their role allows. New accounts do not inherit access to existing workspaces without an authorized invitation.

03

Step-up protection for Plaid

Creating, exchanging, repairing, or disconnecting a financial connection requires an authenticated owner and proof of multi-factor authentication. The server denies the action if that proof is absent.

04

Encryption in transit and at rest

Production traffic uses managed HTTPS. Cloudflare encrypts database and object-storage data at rest. Plaid access tokens are additionally encrypted with AES-GCM before storage and are scrubbed after disconnect.

05

Read-only financial access

Plaid connections can return data for review but cannot initiate transfers. ShopOps never receives a bank password, and imported activity does not change financial totals until an authorized person confirms it.

06

Secure development and vulnerability response

Changes pass linting and automated security/regression tests. Dependency, source, and secret checks run on changes and weekly. Critical findings require immediate containment and a 24-hour remediation or shutdown target.

07

Data minimization and deletion

Versioned consent records the owner’s decision before a new bank connection. Raw Plaid data is deleted after successful disconnect. Workspace owners can export records and start a reviewed permanent-deletion process.

08

Incident response

A documented process covers containment, evidence preservation, investigation, recovery, required notification, and corrective action. Suspected credential or data exposure is treated as urgent.

REPORT A SECURITY CONCERN

Please send enough detail for us to investigate safely.

Email william@integritydrivetrain.com. Do not include passwords, financial-institution credentials, recovery codes, API keys, or live customer exports. If the concern involves active credential exposure, revoke or rotate that credential first when safe to do so.