Zero-Trust Security Architecture

Why connecting Ancore
is safe to do.

Connecting a third-party app to your Shopify admin is a big decision. We designed Ancore from day one around one principle: take the minimum, protect everything, return control instantly.

How your connection works — end to end

01

OAuth Request

Shopify-native OAuth 2.0 flow — no password ever leaves your browser.

02

Token Encrypted

Token encrypted server-side with AES-256-GCM before database write.

03

Read-Only Audit

Token decrypted on-demand in isolated server process. Browser never sees it.

04

Results Returned

Only audit findings are sent to your dashboard. Raw tokens stay server-side.

Four security controls

Minimum Scope

We only ask for what we need.

Ancore Paid Beta requests read_products and read_themes so its server-side scanners can inspect supported catalog and storefront data.

Never requested: orders, transactions, customer PII, billing, or payment data.

Token Security

AES-256 encryption at rest.

Access tokens are encrypted immediately upon receipt using industry-standard AES-256 encryption. Tokens are decrypted only on-demand during active server-side audits.

Tokens are never returned to client browsers, logged to third parties, or stored in plaintext.

Read-Only Default

Paid Beta scans are read-only.

Ancore provides evidence and manual remediation instructions. It does not automatically push product, theme, or policy changes to Shopify.

You make changes in Shopify, then request a new Ancore scan to verify the observed result.

Full Erasure

Uninstall = access revoked.

When Shopify sends a signed app/uninstalled webhook, Ancore marks the store disconnected and removes the stored access token.

Historical findings and receipts are retained until deleted under the account data policy.

Paid Beta Access Scope

What the current Shopify connection does and does not request.

Shopify API ScopeAncore
Product metadata (titles, descriptions, images)
Theme assets
Public policy pages through storefront crawling
Order history & transaction logs
Customer names & contact data
Billing credentials & payment methods
Shopify product or theme write access

✓ = scope requested  ·  ✗ = scope not requested

Security Questions?

Talk to us directly.

If you have questions about our security model, data handling practices, or want to review our OAuth permission scopes before connecting, reach out directly. We review every message and respond within one business day.

Ready to run a secure scan?

Review the full health report before connecting anything. Your first scan is free and requires no Shopify credentials.

Scan Your Store