Security

What we hold, and what we do not claim.

Security pages tend to imply more than they say. This one lists the controls that exist today, states exactly what a verification record contains, and is explicit about the certifications Verify AI does not hold.

The short version

A fraud tool that does not become a customer database

The strongest thing that can be said about the data here is how little of it there is.

On verification

Orders are read, not copied

The payload is analysed and discarded. What persists is the order reference you sent and the conclusion drawn from it.

On access

One workspace cannot see another

Isolation is checked per request against the organization, not inferred from a client-side selection.

On Shopify

Nothing is written to your store

Apart from the risk tag and app metafields. Order status, fulfilment, payment, and customer records are never touched.
Controls

What is in place today

Organization isolation
Every verification, log row, credit balance, API key, and store connection belongs to an organization. Access is checked against it on each request, and members of one cannot read another.
Authentication
Google and GitHub sign-in, with passkey support once an account exists. Sessions are managed by Better Auth.
Roles
Members are invited with roles, and sensitive operations, including connecting a Shopify store and managing billing, require owner or admin rather than mere membership.
API keys
Scoped to an organization, individually revocable, with their own configurable rate limit and per-key usage tracking, so a leaked key is both visible and containable.
Shopify tokens
Access and refresh tokens are stored encrypted with AES-GCM rather than as plaintext columns, and are removed with the connection when a store uninstalls.
Webhook verification
Every Shopify webhook is checked against its HMAC over the exact bytes received. A payload that fails is rejected before it is parsed.
Payments
Card details are handled by Stripe and never reach Verify AI. We store the transaction record, not the instrument.
Infrastructure
Hosted on Google Cloud Platform.
Being explicit

Three things worth stating outright

No published audit report

Verify AI does not currently publish SOC 2 or ISO 27001. If that is a hard requirement for your organization, it is better that you know on this page than three calls in.

TDCCommerce is a separate scope

The Developer Company Inc. offers other services and describes compliance frameworks elsewhere. Those statements cover that work, not automatically this product.

The decision stays yours

Verify AI does not cancel, hold, or refund orders. It reports, and your rules act, which keeps the consequential action under your own audit trail rather than ours.
Data

Data handling

What do you store about our orders?
The order ID you supplied, plus the AI output: score, level, risk factors, reasoning, and recommendations. Nothing else from the payload is written to the database.
So you do not store customer personal data?
Correct, on the verification record. Customer names, emails, phone numbers, addresses, payment details, IP addresses, and user agents are used to produce the assessment and are not persisted with it. That is a deliberate limit rather than a side effect: it makes a data subject request straightforward and means a breach of the verification log does not expose your customers.
What about the Shopify app?
The cached verification on a Shopify order holds the order ID, order name, amount, currency, and the assessment. It is removed when the store uninstalls. Order details are read from Shopify at verification time rather than copied into our database.
Is our data used to train models?
Order data is processed to fulfil the verifications you run and stays scoped to your organization. It is not used to build a shared model or a cross-customer fraud consortium.
Which third parties see the order?
The AI provider that runs the analysis, and the web research and lookup services the checks call. Cached lookups are held so that a repeated IP or search does not go out twice.
Can we delete our data?
Yes. Organizations and their verification logs can be removed from the application, and uninstalling the Shopify app removes the store connection and its cached verifications the same day. For a full account deletion, contact us.
Do you have SOC 2 or ISO 27001?
Verify AI does not currently publish a SOC 2 or ISO 27001 report. If your procurement process requires one, talk to sales, because we would rather tell you now than at the end of an evaluation.
Can you complete a security questionnaire?
Yes. Send it through the contact form marked as sales and we will work through it.

Send the questionnaire before the pilot, not after.

Sales can work through procurement paperwork in parallel with a technical trial.

5 credits on signup · no card required