Security
Security at StoreAdOps
StoreAdOps uses layered controls to reduce risk to user identities, provider connections, and advertising accounts. Security is a shared responsibility, and no internet service can guarantee complete security. This page describes current controls; it does not claim a certification, independent audit, or penetration test that has not occurred.
Identity and access
- Browser access uses verified email magic codes, configured Google Sign-In, or configured reviewer credentials intended for external platform-review workflows.
- API keys are hashed at rest. They are high-entropy bearer credentials. Browser sessions and sign-in codes are also stored as hashes rather than plaintext credentials.
- OAuth tokens are encrypted at rest. Production secrets are stored in a managed secret store and access is restricted to authorized runtime and operator identities.
- Tenant-scoped authorization binds each request to the signed-in or bearer-key user and the provider account that user connected and selected. Cross-account requests are rejected before provider access.
Transport and data protection
- Production traffic uses HTTPS.
- Provider tokens are encrypted before database storage; API keys and sessions are cryptographically hashed.
- StoreAdOps minimizes retained provider data and retrieves campaign, product, inventory, and order information live for user-directed requests rather than maintaining a broad provider-data warehouse.
- Production and staging use separate databases, OAuth clients, encryption secrets, service accounts, API keys, and domains. Production data is not used as staging test data.
Advertising write safety
- Read tools never modify provider accounts.
- Direct write tools require
confirmed=true; approval-backed executions require separately validated execution authority. All provider writes require an idempotency key. - New campaigns are created paused by default so they can be reviewed before delivery.
- Provider write calls are not automatically retried after a platform-side partial or ambiguous failure.
- Write, approval, idempotency, and execution records support duplicate prevention, investigation, and accountability.
- Rate limits, quotas, feature gates, environment ceilings, and emergency-disable controls constrain tool and provider activity.
Application and infrastructure safeguards
- State-changing browser routes validate trusted request origins, and OAuth flows bind short-lived state to the initiating user and expected callback.
- Shopify OAuth and mandatory privacy webhooks require valid HMAC signatures. Provider callbacks validate state and provider-specific authorization requirements.
- Database migrations are versioned and tested for schema consistency. Production images use immutable commit identifiers and deployment checks include public, authentication, and provider-specific smoke tests.
- OAuth callback query strings are excluded from the normal retained request-log sink. Administrative views use field allowlists and do not return encrypted tokens, key hashes, session hashes, or stored secrets.
Monitoring, response, and recovery
StoreAdOps uses cloud-service telemetry and request logs and maintains provider connection-health checks, deployment rollback procedures, automated database backups, credential-rotation procedures, and documented incident runbooks. Some recovery procedures, including a full database-restore drill, have not yet been completed. Suspected incidents are assessed, contained, investigated, and communicated in accordance with applicable legal and contractual requirements. Backups and logs follow their configured retention periods.
Your security responsibilities
- Protect the email account, Google account, StoreAdOps session, API keys, and AI clients you authorize.
- Give keys only to trusted clients, revoke unused or exposed keys, and disconnect providers you no longer use.
- Review every proposed write, monitor advertising spend directly in each platform, and verify provider state after an error or uncertain outcome.
- Promptly report suspected unauthorized access or unexpected provider activity.
Report a security concern
Email support@storeadops.ai with a concise description, affected URL or account, reproduction steps, and contact information. Do not include passwords, API keys, OAuth tokens, customer personal information, or active exploit payloads in email. Please allow reasonable time to investigate before public disclosure.