Security
What we hold, and what we do not claim.
Security pages tend to imply more than they say. This one lists the controls that exist today, states exactly what a verification record contains, and is explicit about the certifications Verify AI does not hold.
The short version
A fraud tool that does not become a customer database
The strongest thing that can be said about the data here is how little of it there is.
On verification
Orders are read, not copied
The payload is analysed and discarded. What persists is the order reference you sent and the conclusion drawn from it.
On access
One workspace cannot see another
Isolation is checked per request against the organization, not inferred from a client-side selection.
On Shopify
Nothing is written to your store
Apart from the risk tag and app metafields. Order status, fulfilment, payment, and customer records are never touched.
Controls
What is in place today
- Organization isolation
- Every verification, log row, credit balance, API key, and store connection belongs to an organization. Access is checked against it on each request, and members of one cannot read another.
- Authentication
- Google and GitHub sign-in, with passkey support once an account exists. Sessions are managed by Better Auth.
- Roles
- Members are invited with roles, and sensitive operations, including connecting a Shopify store and managing billing, require owner or admin rather than mere membership.
- API keys
- Scoped to an organization, individually revocable, with their own configurable rate limit and per-key usage tracking, so a leaked key is both visible and containable.
- Shopify tokens
- Access and refresh tokens are stored encrypted with AES-GCM rather than as plaintext columns, and are removed with the connection when a store uninstalls.
- Webhook verification
- Every Shopify webhook is checked against its HMAC over the exact bytes received. A payload that fails is rejected before it is parsed.
- Payments
- Card details are handled by Stripe and never reach Verify AI. We store the transaction record, not the instrument.
- Infrastructure
- Hosted on Google Cloud Platform.
Being explicit
Three things worth stating outright
No published audit report
Verify AI does not currently publish SOC 2 or ISO 27001. If that is a hard requirement for your organization, it is better that you know on this page than three calls in.
TDCCommerce is a separate scope
The Developer Company Inc. offers other services and describes compliance frameworks elsewhere. Those statements cover that work, not automatically this product.
The decision stays yours
Verify AI does not cancel, hold, or refund orders. It reports, and your rules act, which keeps the consequential action under your own audit trail rather than ours.
Data
Data handling
What do you store about our orders?
The order ID you supplied, plus the AI output: score, level, risk factors, reasoning, and recommendations. Nothing else from the payload is written to the database.
So you do not store customer personal data?
Correct, on the verification record. Customer names, emails, phone numbers, addresses, payment details, IP addresses, and user agents are used to produce the assessment and are not persisted with it. That is a deliberate limit rather than a side effect: it makes a data subject request straightforward and means a breach of the verification log does not expose your customers.
What about the Shopify app?
The cached verification on a Shopify order holds the order ID, order name, amount, currency, and the assessment. It is removed when the store uninstalls. Order details are read from Shopify at verification time rather than copied into our database.
Is our data used to train models?
Order data is processed to fulfil the verifications you run and stays scoped to your organization. It is not used to build a shared model or a cross-customer fraud consortium.
Which third parties see the order?
The AI provider that runs the analysis, and the web research and lookup services the checks call. Cached lookups are held so that a repeated IP or search does not go out twice.
Can we delete our data?
Yes. Organizations and their verification logs can be removed from the application, and uninstalling the Shopify app removes the store connection and its cached verifications the same day. For a full account deletion, contact us.
Do you have SOC 2 or ISO 27001?
Verify AI does not currently publish a SOC 2 or ISO 27001 report. If your procurement process requires one, talk to sales, because we would rather tell you now than at the end of an evaluation.
Can you complete a security questionnaire?
Yes. Send it through the contact form marked as sales and we will work through it.
Send the questionnaire before the pilot, not after.
Sales can work through procurement paperwork in parallel with a technical trial.
5 credits on signup · no card required