Encrypted transport and security headers
The public configuration enforces HTTPS, HSTS, restricted content sources, frame blocking and safe content-type handling.
Security measures reflect the data, permissions and external services actually used by each product or client project.
We use encrypted transport, limited permissions, separated access and defined retention rules.
The public configuration enforces HTTPS, HSTS, restricted content sources, frame blocking and safe content-type handling.
The static website contains public configuration only. SMTP passwords, Shopify secrets and provider tokens are excluded from the client bundle and analytics events.
Shipping and KROS profiles record permissions separately according to the objects they process. Any scope expansion requires a separate review.
Individual Shopify identities use separate credentials, public URLs, encryption keys and database namespaces.
Mandatory Shopify privacy and app-lifecycle handlers process data requests and uninstall events.
Uninstall, a merchant request or loss of purpose starts the applicable deletion process. A legal duty may require restricted retention.
Each product lists its Shopify permissions, processed data, external services, maximum retention and uninstall procedure.
read_orders, read_companies, read_customersread_orders, read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_ordersread_orders, read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_ordersread_orders, read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_ordersScope, measurement and ownership must be stated in the relevant order, SLA or security schedule. Without that agreement, Torevo does not present them as active controls.
Agreed service windows, severity levels and communication procedure.
Recovery objectives only for a system with confirmed backup and recovery architecture.
Scope, assessor, schedule and handling of findings.
Account, network, data or operational-role isolation for the project.
Periods that differ from product defaults and the legal reason for retention.
Evidence scope, frequency and rules for protecting confidential information.
Send security reports to torevo@torevo.tech.
The initial assessment separates product controls, project requirements and evidence required before deployment.