Trust center
Security at Store Grade
Store Grade is designed to review public storefronts while protecting customer workspaces, private reports, and payment workflows.
Current safeguards
- HTTPS transport, strict security headers, anti-framing controls, and restricted browser capabilities.
- Signed, server-validated sessions; role and project-membership checks; revocable private report links.
- Rate limits, one-time login codes, generic authentication failures, and auditable security events.
- Storefront URL validation that blocks private, loopback, link-local, metadata, reserved, and unsupported network targets and revalidates redirects.
- Stripe webhook signature, timestamp, payment-status, and duplicate-event checks.
- Private routes marked non-indexable and non-cacheable.
Customer responsibilities
Protect account credentials and private links, use unique passwords for connected services, maintain theme and code backups, restrict integrations to required permissions, and report suspected compromise promptly.
Report a vulnerability
Email security@storegrade.co with the affected URL, impact, reproducible steps, and safe supporting evidence. Do not access other customers’ data, perform destructive testing, degrade availability, or publish sensitive details before coordinated review.
Data handling
See the Privacy Policy for collection and retention details. General support belongs at support@storegrade.co.