Skip to content

Security, in one sitting.

For technical evaluators. The legal versions live under Policy. Report a vulnerability to contact@eturns.app.

Per-shop isolation

Row-Level Security is the primary control on every shop-scoped table. Application checks are a backup.

No raw PII in model prompts

Case facts use sentinel IDs and structured fields. Email, name, and address do not go to the language models.

HMAC and idempotent webhooks

Every Shopify webhook is verified before work starts, then de-duplicated. GDPR webhooks return 401 on a bad HMAC.

Audit trail

Every AI decision stores the model, prompt hash, context summary, tool calls, action, dollar amount, and reasoning. Retained 7 years.

Where data lives

Persisted data is in Supabase on AWS ap-south-1 (Mumbai). The app and queue run on Render in Singapore. Transfers are described in the Privacy Policy.

SOC 2

Brand-tier merchants get attestation access when the audit is complete. We do not claim a completed SOC 2 report today.