Skip to content
Back to Home

Security

Last updated: 21 August 2026

At GoPrimy, security is a top priority. We are committed to protecting your data with industry best practices, modern infrastructure, and a culture of continuous improvement.

1. Infrastructure Security

GoPrimy is hosted on trusted cloud providers with strong physical and network protections, including:

  • Secure data centers with 24/7 surveillance and biometric access controls
  • Regularly updated firewalls and DDoS protection
  • Encrypted data storage and transport (HTTPS/TLS 1.2+)

Data Encryption

  • All data in transit is encrypted using HTTPS with TLS 1.2 or higher
  • Sensitive data is encrypted at rest using strong AES-256 encryption
  • API keys and access tokens are securely stored and never exposed

3. Access Controls

  • Access to systems is limited based on role and need-to-know principles
  • Two-factor authentication (2FA) is enforced for internal tools
  • Audit logs are maintained for sensitive operations

4. Application Security

  • Regular code reviews and vulnerability scanning
  • Input sanitization and protection against common threats (e.g., XSS, CSRF)
  • Rate limiting and abuse detection for APIs and endpoints

5. Shopify Integration Security

GoPrimy uses Shopify OAuth for authentication and permission control. We request these scopes and no others: read_orders, read_customers, read_returns, read_legal_policies, read_products, read_checkouts, write_checkouts, read_discounts, write_discounts, write_script_tags, and write_payment_terms. The write scopes exist so an AI employee can apply a discount or adjust a checkout within the limits you set.

All data access is scoped per store and protected by Shopify's API authorization framework.

6. Vendor & Subprocessor Security

We work only with carefully vetted vendors and subprocessors. All subprocessors must meet our security and data protection standards, and are subject to contractual obligations.

7. Data Backups and Recovery

  • Regular automated backups are performed for core systems
  • Backups are encrypted and stored securely
  • Disaster recovery procedures are tested periodically

8. Responsible Disclosure

We welcome security researchers to responsibly disclose any vulnerabilities they discover. If you believe you've found a security issue, please contact us immediately at contact@goprimy.com.

9. Compliance and Best Practices

GoPrimy follows industry standards including:

  • GDPR and CCPA principles
  • OWASP Top 10 security guidelines
  • Secure development lifecycle practices

10. Contact

If you have any questions about our security practices, please contact us:

We take your trust seriously and are committed to maintaining a secure and resilient platform.